05-13-2020 09:13 AM
Hello All,
I am getting an error message in the CLI : "MAC decrypt: MAC length error"
We are running ASA 9.14(1)
Error repeats itself approximately 3-4 minutes...
Solved! Go to Solution.
05-15-2020 12:39 PM
I apologize for such a delayed response.
I wanted to follow up with our solution. We viewed the firewall logs and were getting an NTP packet refusal. I removed our NTP server configs on the firewall and re-added them AFTER I reconfigured the switch that serves time on our network. I removed and re-added the NTP server settings on the switch and verified our ASA successfully pulled time. Once it did that, the error messages ceased.
Thank you for the valuable input and have a great day!
05-13-2020 10:49 AM
Seems that there is a mismatch in your HMAC configuration in one of your VPNs. But you did not provide much information to go on so this is what first comes to mind.
05-13-2020 10:52 AM
05-13-2020 11:18 AM
Well, check the HMAC configuration first and if that doesn't pan out then you could provide the following:
a description of your network (what connects to the ASA, a switch, router, etc.)
- What roll the ASA plays in your network (just VPN or also a gateway to the internet)? I suppose this could fall under the network description also.
- How many VPNs do you have and how many are reporting this error?
- Were there any changes made prior to seeing this error? Or is this a new VPN setup?
05-15-2020 12:39 PM
I apologize for such a delayed response.
I wanted to follow up with our solution. We viewed the firewall logs and were getting an NTP packet refusal. I removed our NTP server configs on the firewall and re-added them AFTER I reconfigured the switch that serves time on our network. I removed and re-added the NTP server settings on the switch and verified our ASA successfully pulled time. Once it did that, the error messages ceased.
Thank you for the valuable input and have a great day!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide