02-18-2019 12:02 PM - last edited on 05-14-2020 08:57 AM by thomas
Hi Everyone,
I am trying to form a SXP sesstion between ASA and WS-C3850-12S-S switch .
Commands on switch :
cts sxp enable
cts sxp default source-ip 10.100.8.22
cts sxp default password testing
cts sxp connection peer 10.10.8.1 source 10.100.8.22 password default mode local speaker hold-time 0
----------------------------------------------------------------------------------------
Commands on ASA:
cts sxp enable
cts sxp default password testing
cts sxp default source-ip 10.100.8.1
cts sxp connection peer 10.100.8.22 source 10.100.8.1 password default mode local listener
------------------------------------------------------------------------------------
But the connection status is still off as shown below
Sw(config)#do sh cts sxp conn
SXP : Enabled
Highest Version Supported: 4
Default Password : Set
Default Source IP: 10.100.8.22
Connection retry open period: 120 secs
Reconcile period: 120 secs
Retry open timer is running
Peer-Sequence traverse limit for export: Not Set
Peer-Sequence traverse limit for import: Not Set
----------------------------------------------
Peer IP : 10.10.8.1
Source IP : 10.100.8.22
Conn status : Off
Conn version : 4
Local mode : SXP Speaker
Connection inst# : 1
TCP conn fd : -1
TCP conn password: default SXP password
Duration since last state change: 0:00:01:02 (dd:hr:mm:sec)
---------------------------------------------------------------------------------
Below are the log messages which it shows .
*Feb 18 19:56:07.347: CTS-SXP-CONN:sxp_process_message_event = CTS_SXPMSG_REQUES T
*Feb 18 19:56:07.348: CTS-SXP-CONN:sxp_process_request CTS_SXPMSG_REQ_SHOWCONN
*Feb 18 19:56:07.348: CTS-SXP-INTNL:sxp_conn_wavl_cmp_tableid tableid1 0x0, tabl eid2 0x0, ip1 10.10.8.1, ip2 0.0.0.0 conn_mode1 1 conn_mode2 1
*Feb 18 19:56:07.348: CTS-SXP-INTNL:sxp_get_next_conn_by_tableid conn:0x3DCB197C , peer ip:10.10.8.1, tableid:0x0
*Feb 18 19:56:07.348: CTS-SXP-INTNL:sxp_conn_wavl_cmp_tableid tableid1 0x0, tabl eid2 0x0, ip1 10.10.8.1, ip2 10.10.8.1 conn_mode1 1 conn_mode2 1
*Feb 18 19:56:07.348: CTS-SXP-INTNL:sxp_get_next_conn_by_tableid conn:0x0, peer ip:0.0.0.0, tableid:0x0
*Feb 18 19:56:07.348: CTS-SXP-INTNL:cdb_get_next_entry
*Feb 18 19:56:07.348: CTS-SXP-INTNL:cdb_get_next_entry
*Feb 18 19:56:07.348: CTS-SXP-INTNL:sxp_process_request boolean set
*Feb 18 19:56:07.348: CTS-SXP-INTNL:sxp_send_request set boolean after
*Feb 18 19:56:16.998: CTS-SXP-CONN:is_cts_sxp_rf_active
*Feb 18 19:56:16.999: CTS-SXP-CONN:ph_retry_open_timer
*Feb 18 19:56:16.999: CTS-SXP-CONN:ph_retry_open_timer retry timer stopped
*Feb 18 19:56:16.999: CTS-SXP-INTNL:cdb_get_next_entry
*Feb 18 19:56:16.999: CTS-SXP-CONN:retry conn setup; conn index = 1
*Feb 18 19:56:16.999: CTS-SXP-CONN:sh_re_setup_conn conn_index = 1
*Feb 18 19:56:16.999: CTS-SXP-CONN:conn_cleanup <-1>
*Feb 18 19:56:16.999: sxp_calc_src_ip cfg src: 10.100.8.22, def src: 10.100.8.22 calc src: 10.100.8.22 vrf:, tableid:0x0
*Feb 18 19:56:16.999: CTS-SXP-CONN:sxp_socket_open vrf:, tablied:0x0 src_ip = 10.100.8.22
*Feb 18 19:56:16.999: CTS-SXP-CONN:SXP SCM: socket open fd = 1, src_ip = 10.100.8.22
*Feb 18 19:56:17.002: CTS-SXP-CONN:ph_send_open <1> fd: 1, <10.10.8.1, 10.100.8.22>
*Feb 18 19:56:17.002: CTS-SXP-INTNL:sxp_fd_hash_table_entry_find cdbp 1, <10.10.8.1, 10.100.8.22>
*Feb 18 19:56:17.002: CTS-SXP-CONN:get_conn_passwd_info <10.10.8.1, 10.100.8.22>
*Feb 18 19:56:17.002: CTS-SXP-CONN:sxp_socket_upd_md5_option <10.10.8.1, 10.100.8.22>
*Feb 18 19:56:17.002: CTS-SXP-CONN:SXP SCM: socket_connect result:-1, fd:1;errno = 265, No route to host, <10.10.8.1, 10.100.8.22>
*Feb 18 19:56:17.002: CTS-SXP-ERR:SXP SCM: socket_connect failed
*Feb 18 19:56:17.002: CTS-SXP-CONN:conn_cleanup <1>
*Feb 18 19:56:17.002: CTS-SXP-INTNL:sxp_fd_hash_table_entry_find cdbp 1, <10.10.8.1, 10.100.8.22>
*Feb 18 19:56:17.002: CTS-SXP-INTNL:sxp_fd_hash_table_entry_find cdbp 1, <10.10.8.1, 10.100.8.22>
*Feb 18 19:56:17.002: CTS-SXP-CONN:free_conn_buffers, <10.10.8.1, 10.100.8.22>
*Feb 18 19:56:17.003: CTS-SXP-CONN:conn_cleanup retry timer started
*Feb 18 19:56:17.003: CTS-SXP-INTNL:cdb_get_next_entry
*Feb 18 19:56:17.003: CTS-SXP-CONN:ph_retry_open_timer retry timer started
*Feb 18 19:57:11.925: CTS-SXP-CONN:Received invalid DIRECT_EVENT
*Feb 18 19:57:11.927: CTS-SXP-CONN:Received invalid DIRECT_EVENT
*Feb 18 19:57:11.928: CTS-SXP-CONN:is_cts_sxp_rf_active
*Feb 18 19:57:11.928: CTS-SXP-INTNL:sxp_fd_hash_table_entry_find cdbp 0, <0.0.0.0, 0.0.0.0>
*Feb 18 19:57:11.928: CTS-SXP-ERR:conn index out of range, ci=-1
*Feb 18 19:57:11.928: CTS-SXP-CONN:Received Socket event; sock_ev = 1 fd: 0, <0.0.0.0, 0.0.0.0>
*Feb 18 19:57:11.928: CTS-SXP-CONN:scm_handle_accept_sock <0>
*Feb 18 19:57:11.928: CTS-SXP-CONN:sxp_cfg_wavl_cmp_vrfname vrf name1 , vrf name2 , ip1 10.10.8.1, ip2 10.100.8.1 conn mode1 1, conn_mode2 1
*Feb 18 19:57:11.928: CTS-SXP-INTNL:sxp_cfg_wavl_cmp_vrfname vrf name1 , vrf name2 , ip1 10.10.8.1, ip2 10.100.8.1 conn mode1 1,conn_mode2 1
*Feb 18 19:57:11.928: CTS-SXP-CONN:sxp_cfg_wavl_cmp_vrfname vrf name1 , vrf name2 , ip1 10.10.8.1, ip2 10.100.8.1 conn mode1 1, conn_mode2 2
*Feb 18 19:57:11.928: CTS-SXP-INTNL:sxp_cfg_wavl_cmp_vrfname vrf name1 , vrf name2 , ip1 10.10.8.1, ip2 10.100.8.1 conn mode1 1,conn_mode2 2
*Feb 18 19:57:11.928: CTS-SXP-ERR:SXP SCM: configuration error: <10.100.8.1, 10.100.8.22> fd = 1 cfg:0x0, conndb:0x0
Can anyone figure out anything from this?
Solved! Go to Solution.
02-19-2019 06:36 AM
Perhaps the SXP connections not permitted. See TrustSec Troubleshooting Guide
Other TrustSec resources at Segmentation & Group-Based Policy Resou... - Cisco Community
02-19-2019 11:26 AM
02-18-2019 12:06 PM
*Feb 18 20:11:49.637: CTS-SXP-CONN:sxp_process_message_event = CTS_SXPMSG_REQUEST
*Feb 18 20:11:49.637: CTS-SXP-CONN:sxp_process_request CTS_SXPMSG_REQ_SHOWCONN
*Feb 18 20:11:49.637: CTS-SXP-INTNL:sxp_conn_wavl_cmp_tableid tableid1 0x0, tableid2 0x0, ip1 10.10.8.1, ip2 0.0.0.0 conn_mode1 1 conn_mode2 1
*Feb 18 20:11:49.637: CTS-SXP-INTNL:sxp_get_next_conn_by_tableid conn:0x3DCB197C, peer ip:10.10.8.1, tableid:0x0
*Feb 18 20:11:49.637: CTS-SXP-INTNL:sxp_conn_wavl_cmp_tableid tableid1 0x0, tableid2 0x0, ip1 10.10.8.1, ip2 10.10.8.1 conn_mode1 1 conn_mode2 1
*Feb 18 20:11:49.637: CTS-SXP-INTNL:sxp_get_next_conn_by_tableid conn:0x0, peer ip:0.0.0.0, tableid:0x0
*Feb 18 20:11:49.637: CTS-SXP-INTNL:cdb_get_next_entry
*Feb 18 20:11:49.637: CTS-SXP-INTNL:cdb_get_next_entry
*Feb 18 20:11:49.637: CTS-SXP-INTNL:sxp_process_request boolean set
*Feb 18 20:11:49.638: CTS-SXP-INTNL:sxp_send_request set boolean after
*Feb 18 20:12:16.998: CTS-SXP-CONN:is_cts_sxp_rf_active
*Feb 18 20:12:16.998: CTS-SXP-CONN:ph_retry_open_timer
*Feb 18 20:12:16.998: CTS-SXP-CONN:ph_retry_open_timer retry timer stopped
*Feb 18 20:12:16.998: CTS-SXP-INTNL:cdb_get_next_entry
*Feb 18 20:12:16.998: CTS-SXP-CONN:retry conn setup; conn index = 1
*Feb 18 20:12:16.998: CTS-SXP-CONN:sh_re_setup_conn conn_index = 1
*Feb 18 20:12:16.998: CTS-SXP-CONN:conn_cleanup <-1>
*Feb 18 20:12:16.998: sxp_calc_src_ip cfg src: 10.100.8.22, def src: 10.100.8.22 calc src: 10.100.8.22 vrf:, tableid:0x0
*Feb 18 20:12:16.998: CTS-SXP-CONN:sxp_socket_open vrf:, tablied:0x0 src_ip = 10.100.8.22
*Feb 18 20:12:16.999: CTS-SXP-CONN:SXP SCM: socket open fd = 1, src_ip = 10.100.8.22
*Feb 18 20:12:17.001: CTS-SXP-CONN:ph_send_open <1> fd: 1, <10.10.8.1, 10.100.8.22>
*Feb 18 20:12:17.002: CTS-SXP-INTNL:sxp_fd_hash_table_entry_find cdbp 1, <10.10.8.1, 10.100.8.22>
*Feb 18 20:12:17.002: CTS-SXP-CONN:get_conn_passwd_info <10.10.8.1, 10.100.8.22>
*Feb 18 20:12:17.002: CTS-SXP-CONN:sxp_socket_upd_md5_option <10.10.8.1, 10.100.8.22>
*Feb 18 20:12:17.002: CTS-SXP-CONN:SXP SCM: socket_connect result:-1, fd:1;errno = 265, No route to host, <10.10.8.1, 10.100.8.22>
*Feb 18 20:12:17.002: CTS-SXP-ERR:SXP SCM: socket_connect failed
*Feb 18 20:12:17.002: CTS-SXP-CONN:conn_cleanup <1>
*Feb 18 20:12:17.002: CTS-SXP-INTNL:sxp_fd_hash_table_entry_find cdbp 1, <10.10.8.1, 10.100.8.22>
*Feb 18 20:12:17.002: CTS-SXP-INTNL:sxp_fd_hash_table_entry_find cdbp 1, <10.10.8.1, 10.100.8.22>
*Feb 18 20:12:17.002: CTS-SXP-CONN:free_conn_buffers, <10.10.8.1, 10.100.8.22>
*Feb 18 20:12:17.002: CTS-SXP-CONN:conn_cleanup retry timer started
*Feb 18 20:12:17.002: CTS-SXP-INTNL:cdb_get_next_entry
*Feb 18 20:12:17.002: CTS-SXP-CONN:ph_retry_open_timer retry timer started
*Feb 18 20:13:11.986: CTS-SXP-CONN:Received invalid DIRECT_EVENT
*Feb 18 20:13:11.988: CTS-SXP-CONN:Received invalid DIRECT_EVENT
*Feb 18 20:13:11.988: CTS-SXP-CONN:is_cts_sxp_rf_active
*Feb 18 20:13:11.989: CTS-SXP-INTNL:sxp_fd_hash_table_entry_find cdbp 0, <0.0.0.0, 0.0.0.0>
*Feb 18 20:13:11.989: CTS-SXP-ERR:conn index out of range, ci=-1
*Feb 18 20:13:11.989: CTS-SXP-CONN:Received Socket event; sock_ev = 1 fd: 0, <0.0.0.0, 0.0.0.0>
*Feb 18 20:13:11.989: CTS-SXP-CONN:scm_handle_accept_sock <0>
*Feb 18 20:13:11.989: CTS-SXP-CONN:sxp_cfg_wavl_cmp_vrfname vrf name1 , vrf name2 , ip1 10.10.8.1, ip2 10.100.8.1 conn mode1 1, conn_mode2 1
*Feb 18 20:13:11.989: CTS-SXP-INTNL:sxp_cfg_wavl_cmp_vrfname vrf name1 , vrf name2 , ip1 10.10.8.1, ip2 10.100.8.1 conn mode1 1,conn_mode2 1
*Feb 18 20:13:11.989: CTS-SXP-CONN:sxp_cfg_wavl_cmp_vrfname vrf name1 , vrf name2 , ip1 10.10.8.1, ip2 10.100.8.1 conn mode1 1, conn_mode2 2
*Feb 18 20:13:11.989: CTS-SXP-INTNL:sxp_cfg_wavl_cmp_vrfname vrf name1 , vrf name2 , ip1 10.10.8.1, ip2 10.100.8.1 conn mode1 1,conn_mode2 2
*Feb 18 20:13:11.989: CTS-SXP-ERR:SXP SCM: configuration error: <10.100.8.1, 10.100.8.22> fd = 1 cfg:0x0, conndb:0x0
*Feb 18 20:13:11.989: CTS-SXP-CONN:Received invalid DIRECT_EVENT
*Feb 18 20:14:16.998: CTS-SXP-CONN:is_cts_sxp_rf_active
*Feb 18 20:14:16.998: CTS-SXP-CONN:ph_retry_open_timer
*Feb 18 20:14:16.998: CTS-SXP-CONN:ph_retry_open_timer retry timer stopped
*Feb 18 20:14:16.998: CTS-SXP-INTNL:cdb_get_next_entry
*Feb 18 20:14:16.998: CTS-SXP-CONN:retry conn setup; conn index = 1
*Feb 18 20:14:16.998: CTS-SXP-CONN:sh_re_setup_conn conn_index = 1
*Feb 18 20:14:16.998: CTS-SXP-CONN:conn_cleanup <-1>
*Feb 18 20:14:16.998: sxp_calc_src_ip cfg src: 10.100.8.22, def src: 10.100.8.22 calc src: 10.100.8.22 vrf:, tableid:0x0
*Feb 18 20:14:16.998: CTS-SXP-CONN:sxp_socket_open vrf:, tablied:0x0 src_ip = 10.100.8.22
*Feb 18 20:14:16.999: CTS-SXP-CONN:SXP SCM: socket open fd = 1, src_ip = 10.100.8.22
*Feb 18 20:14:17.002: CTS-SXP-CONN:ph_send_open <1> fd: 1, <10.10.8.1, 10.100.8.22>
*Feb 18 20:14:17.002: CTS-SXP-INTNL:sxp_fd_hash_table_entry_find cdbp 1, <10.10.8.1, 10.100.8.22>
*Feb 18 20:14:17.002: CTS-SXP-CONN:get_conn_passwd_info <10.10.8.1, 10.100.8.22>
*Feb 18 20:14:17.002: CTS-SXP-CONN:sxp_socket_upd_md5_option <10.10.8.1, 10.100.8.22>
*Feb 18 20:14:17.002: CTS-SXP-CONN:SXP SCM: socket_connect result:-1, fd:1;errno = 265, No route to host, <10.10.8.1, 10.100.8.22>
*Feb 18 20:14:17.002: CTS-SXP-ERR:SXP SCM: socket_connect failed
*Feb 18 20:14:17.002: CTS-SXP-CONN:conn_cleanup <1>
*Feb 18 20:14:17.002: CTS-SXP-INTNL:sxp_fd_hash_table_entry_find cdbp 1, <10.10.8.1, 10.100.8.22>
*Feb 18 20:14:17.002: CTS-SXP-INTNL:sxp_fd_hash_table_entry_find cdbp 1, <10.10.8.1, 10.100.8.22>
*Feb 18 20:14:17.002: CTS-SXP-CONN:free_conn_buffers, <10.10.8.1, 10.100.8.22>
*Feb 18 20:14:17.002: CTS-SXP-CONN:conn_cleanup retry timer started
*Feb 18 20:14:17.002: CTS-SXP-INTNL:cdb_get_next_entry
*Feb 18 20:14:17.002: CTS-SXP-CONN:ph_retry_open_timer retry timer started
02-18-2019 12:14 PM
02-18-2019 11:04 PM
Hey Damien,
Apologies , it was my typo . I tried to change the IP's for confidentiality .
It is 10.100.8.1 as it should be.
I do this all the time and it does not give me any issue at all . Its just this time I enabled it on ASA first , rather than Switch . Does it really make any difference?
I have tried disabling and reenabling it , shut and no shut SVI of the switch , clearing cts sxp config from both ends and reconfiguring them, finally reloading the Swith as well as ASA and it did not come out.
Can you please share me any documents which guides about best practise in SXP , if you have any?
Your help is hightly appreciated .
Thanks ,
Saurabh Dhakate
02-19-2019 06:36 AM
Perhaps the SXP connections not permitted. See TrustSec Troubleshooting Guide
Other TrustSec resources at Segmentation & Group-Based Policy Resou... - Cisco Community
02-19-2019 11:26 AM
05-16-2020 05:29 PM
The authoritative guide for switch to ASA would be the TrustSec User to Data Center Access Control Design Guide.
Find others at http://cs.co/ise-guides#TrustSec
05-13-2020 07:49 AM
Have you solved this ? We have a problem SXP problem with ASA and IOS-XE too
05-13-2020 08:32 AM
As per the logs, it looks like the routing issue on switch:
*Feb 18 19:56:17.002: CTS-SXP-CONN:sxp_socket_upd_md5_option <10.10.8.1, 10.100.8.22>
*Feb 18 19:56:17.002: CTS-SXP-CONN:SXP SCM: socket_connect result:-1, fd:1;errno = 265, No route to host, <10.10.8.1, 10.100.8.22>
*Feb 18 19:56:17.002: CTS-SXP-ERR:SXP SCM: socket_connect failed
05-14-2020 09:46 AM
I remember that's the first thing which I had tested. Both peers were pingable to each other bidirectionally. Thanks!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide