cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1216
Views
0
Helpful
0
Replies

ASR920 giving out crypto erros

dees
Level 1
Level 1

Hi,

While trying to setup IPsec using crypto map I noticed I was getting this error(which didn't work). Even after removing the config I am still getting these errors.  Does it have any significance on IPSEC not working?

 

Jan 25 15:15:34.145: CRYPTO_ENGINE: saving keys
Jan 25 15:15:34.145: CRYPTO_ENGINE: found key sr.xxxx.com for save attempt
Jan 25 15:15:34.146: CRYPTO_ENGINE: found key sr.xxxx.com.server for save attempt
Jan 25 15:15:34.146: CRYPTO_ENGINE: skipping temp key sr.xxxx.com.server

Jan 25 15:15:34.147: crypto_engine_select_crypto_engine: can't handle any more

 

sr#show platform
Chassis type: ASR-920U-12SZ-IM

Slot Type State Insert time (ago)
--------- ------------------- --------------------- -----------------
0/0 12xGE-4x10GE-FIXED ok 01:00:02
R0 ASR-920U-12SZ-IM ok, active 01:04:02
F0 ok, active 01:04:02
P0 ASR920-PSU0 ok 01:02:48
P1 ASR920-PSU1 ok 01:02:44
P2 ASR920-FAN ok 01:02:47

Slot CPLD Version Firmware Version
--------- ------------------- ---------------------------------------
R0 16112910 15.5(3r)S2
F0 16112910 15.5(3r)S2

 



sr#show crypto engine
% Incomplete command.

sr#show crypto engine ?
% Unrecognized command
sr#show crypto engine

 

 

My ipsec config was

 

crypto isakmp policy 10
encryption aes 256
authentication pre-share
group 14
lifetime 180
crypto isakmp key xxx address xxx
!
!
crypto ipsec transform-set aesset esp-aes 256 esp-sha-hmac
mode transport
!
crypto map aesmap 10 ipsec-isakmp
set peer xxx
set transform-set aesset
match address 120
!

 

0 Replies 0