cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1176
Views
0
Helpful
4
Replies

Firepower remains of VPN connections on the sensor settings.

pr0g
Level 1
Level 1

Hello!

Firepower: v6.5

Faced a situation when VPN connections were deleted on FMC, but they remained on FTD.

crypto map CSM_outside_main_map 2 set peer XXX.175.186.85
crypto map CSM_outside_main_map 2 set ikev2 ipsec-proposal CSM_IP_1
crypto map CSM_outside_main_map 2 set reverse-route
crypto map CSM_OUTSIDE-BACKUP_map 2 set pfs
crypto map CSM_OUTSIDE-BACKUP_map 2 set peer XXX.175.186.85 XXX.214.6.133
crypto map CSM_OUTSIDE-BACKUP_map 2 set ikev2 ipsec-proposal CSM_IP_2
crypto map CSM_OUTSIDE-BACKUP_map 2 set reverse-route
...

Any ideas on how to remove them?

4 Replies 4

Marvin Rhoads
Hall of Fame
Hall of Fame

I've seen artifiacts like this on ocassion. At one point there was a bug ID tracking it but then it was supposed to have been resolved. More recently I had the opposite (with FDM) - the site-to-site VPNs were present in the FDM GUI (with no deploy pending) but no crypto map sequences in the running-config.

What versions are you running (FMC and FTD)?

FMC - 6.5.0.4

FTD - 6.5.0

pr0g
Level 1
Level 1

Today during deployment I noticed an unassigned VPN. It is not on the VPN list.

It definitely looks like a bug. I'd recommend opening a TAC case for confirmation and a possible work around.

Review Cisco Networking for a $25 gift card