<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA5510 : dynamic vpn problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5510-dynamic-vpn-problem/m-p/1089175#M894142</link>
    <description>&lt;P&gt;hi all, &lt;/P&gt;&lt;P&gt;     I'm using ASA5510 and Zyxel routers to do site-to-site vpn. Because all of Zyxel routers are using ADSL(dynamic IP address). I decided to use dynamic vpn on the ASA. The serious problem is that when the tunnels have been built and then some tunnel will be brought down . I tried to debug. The messages are as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Oct 29 13:27:16 [IKEv1 DEBUG]: Pitcher: received key delete msg, spi 0x62b09b4d&lt;/P&gt;&lt;P&gt;Oct 29 13:27:16 [IKEv1]: IP = xx.xx.xx.xx, IKE_DECODE RECEIVED Message (msgid=ee723a0d) with payloads : HDR + HASH (8) + DELETE (1&lt;/P&gt;&lt;P&gt;2) + NONE (0) total length : 76&lt;/P&gt;&lt;P&gt;Oct 29 13:27:16 [IKEv1 DEBUG]: Group = DefaultL2LGroup, IP = xx.xx.xx.xx, processing hash payload&lt;/P&gt;&lt;P&gt;Oct 29 13:27:16 [IKEv1 DEBUG]: Group = DefaultL2LGroup, IP = xx.xx.xx.xx, processing delete&lt;/P&gt;&lt;P&gt;Oct 29 13:27:16 [IKEv1]: Group = DefaultL2LGroup, IP = xx.xx.xx.xx, Connection terminated for peer DefaultL2LGroup.  Reason: Peer &lt;/P&gt;&lt;P&gt;Terminate  Remote Proxy N/A, Local Proxy N/A&lt;/P&gt;&lt;P&gt;Oct 29 13:27:16 [IKEv1 DEBUG]: Group = DefaultL2LGroup, IP = xx.xx.xx.xx, sending delete/delete with reason message&lt;/P&gt;&lt;P&gt;Oct 29 13:27:16 [IKEv1 DEBUG]: Group = DefaultL2LGroup, IP = xx.xx.xx.xx, constructing blank hash payload&lt;/P&gt;&lt;P&gt;Oct 29 13:27:16 [IKEv1 DEBUG]: Group = DefaultL2LGroup, IP = xx.xx.xx.xx, constructing IPSec delete payload&lt;/P&gt;&lt;P&gt;Oct 29 13:27:16 [IKEv1 DEBUG]: Group = DefaultL2LGroup, IP = xx.xx.xx.xx, constructing qm hash payload&lt;/P&gt;&lt;P&gt;Oct 29 13:27:16 [IKEv1]: IP = xx.xx.xx.xx, IKE_DECODE SENDING Message (msgid=507e92d8) with payloads : HDR + HASH (8) + DELETE (12&lt;/P&gt;&lt;P&gt;) + NONE (0) total length : 64&lt;/P&gt;&lt;P&gt;Oct 29 13:27:16 [IKEv1 DEBUG]: Group = DefaultL2LGroup, IP = xx.xx.xx.xx, Active unit receives a delete event for remote peer xx.xx.xx.xx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Oct 29 13:27:16 [IKEv1 DEBUG]: Group = DefaultL2LGroup, IP = xx.xx.xx.xx, IKE Deleting SA: Remote Proxy 192.3.11.0, Local Proxy 17&lt;/P&gt;&lt;P&gt;2.16.0.0&lt;/P&gt;&lt;P&gt;Oct 29 13:27:16 [IKEv1]: Group = DefaultL2LGroup, IP = xx.xx.xx.xx, Deleting static route for L2L peer that came in on a dynamic m&lt;/P&gt;&lt;P&gt;ap. address: 192.3.11.0, mask: 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not sure why the Zyxel sent the delete message to the ASA. Then ASA processes that message. As a result, The tunnel has to be re-built.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It always happens. Normally, it should not be a problem as long as the tunnel is still up and packets are being passed through the tunnel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Toshi&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 14:06:53 GMT</pubDate>
    <dc:creator>Thotsaphon Lueangwattanaphong</dc:creator>
    <dc:date>2019-03-11T14:06:53Z</dc:date>
    <item>
      <title>ASA5510 : dynamic vpn problem</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-dynamic-vpn-problem/m-p/1089175#M894142</link>
      <description>&lt;P&gt;hi all, &lt;/P&gt;&lt;P&gt;     I'm using ASA5510 and Zyxel routers to do site-to-site vpn. Because all of Zyxel routers are using ADSL(dynamic IP address). I decided to use dynamic vpn on the ASA. The serious problem is that when the tunnels have been built and then some tunnel will be brought down . I tried to debug. The messages are as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Oct 29 13:27:16 [IKEv1 DEBUG]: Pitcher: received key delete msg, spi 0x62b09b4d&lt;/P&gt;&lt;P&gt;Oct 29 13:27:16 [IKEv1]: IP = xx.xx.xx.xx, IKE_DECODE RECEIVED Message (msgid=ee723a0d) with payloads : HDR + HASH (8) + DELETE (1&lt;/P&gt;&lt;P&gt;2) + NONE (0) total length : 76&lt;/P&gt;&lt;P&gt;Oct 29 13:27:16 [IKEv1 DEBUG]: Group = DefaultL2LGroup, IP = xx.xx.xx.xx, processing hash payload&lt;/P&gt;&lt;P&gt;Oct 29 13:27:16 [IKEv1 DEBUG]: Group = DefaultL2LGroup, IP = xx.xx.xx.xx, processing delete&lt;/P&gt;&lt;P&gt;Oct 29 13:27:16 [IKEv1]: Group = DefaultL2LGroup, IP = xx.xx.xx.xx, Connection terminated for peer DefaultL2LGroup.  Reason: Peer &lt;/P&gt;&lt;P&gt;Terminate  Remote Proxy N/A, Local Proxy N/A&lt;/P&gt;&lt;P&gt;Oct 29 13:27:16 [IKEv1 DEBUG]: Group = DefaultL2LGroup, IP = xx.xx.xx.xx, sending delete/delete with reason message&lt;/P&gt;&lt;P&gt;Oct 29 13:27:16 [IKEv1 DEBUG]: Group = DefaultL2LGroup, IP = xx.xx.xx.xx, constructing blank hash payload&lt;/P&gt;&lt;P&gt;Oct 29 13:27:16 [IKEv1 DEBUG]: Group = DefaultL2LGroup, IP = xx.xx.xx.xx, constructing IPSec delete payload&lt;/P&gt;&lt;P&gt;Oct 29 13:27:16 [IKEv1 DEBUG]: Group = DefaultL2LGroup, IP = xx.xx.xx.xx, constructing qm hash payload&lt;/P&gt;&lt;P&gt;Oct 29 13:27:16 [IKEv1]: IP = xx.xx.xx.xx, IKE_DECODE SENDING Message (msgid=507e92d8) with payloads : HDR + HASH (8) + DELETE (12&lt;/P&gt;&lt;P&gt;) + NONE (0) total length : 64&lt;/P&gt;&lt;P&gt;Oct 29 13:27:16 [IKEv1 DEBUG]: Group = DefaultL2LGroup, IP = xx.xx.xx.xx, Active unit receives a delete event for remote peer xx.xx.xx.xx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Oct 29 13:27:16 [IKEv1 DEBUG]: Group = DefaultL2LGroup, IP = xx.xx.xx.xx, IKE Deleting SA: Remote Proxy 192.3.11.0, Local Proxy 17&lt;/P&gt;&lt;P&gt;2.16.0.0&lt;/P&gt;&lt;P&gt;Oct 29 13:27:16 [IKEv1]: Group = DefaultL2LGroup, IP = xx.xx.xx.xx, Deleting static route for L2L peer that came in on a dynamic m&lt;/P&gt;&lt;P&gt;ap. address: 192.3.11.0, mask: 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not sure why the Zyxel sent the delete message to the ASA. Then ASA processes that message. As a result, The tunnel has to be re-built.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It always happens. Normally, it should not be a problem as long as the tunnel is still up and packets are being passed through the tunnel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Toshi&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:06:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-dynamic-vpn-problem/m-p/1089175#M894142</guid>
      <dc:creator>Thotsaphon Lueangwattanaphong</dc:creator>
      <dc:date>2019-03-11T14:06:53Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5510 : dynamic vpn problem</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-dynamic-vpn-problem/m-p/1089176#M894149</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi again,&lt;/P&gt;&lt;P&gt;I just changed from ASA to ISR router(IOS Sec). Router did okay although it got lots of error messages. The tunnel is still up though.&lt;/P&gt;&lt;P&gt;F.e. Router Error.&lt;/P&gt;&lt;P&gt;%CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=y.y.y.y, prot=50, spi=0x28DA0254(685376084), srcaddr=x.x.x.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I configured as this link,&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807ea936.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807ea936.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea?&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;Toshi &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Nov 2008 15:46:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-dynamic-vpn-problem/m-p/1089176#M894149</guid>
      <dc:creator>Thotsaphon Lueangwattanaphong</dc:creator>
      <dc:date>2008-11-03T15:46:28Z</dc:date>
    </item>
  </channel>
</rss>

