07-05-2021 01:19 AM
Hello
I have an issue with ASA FW that is used for VPN purposes.
I see a lot of dropped packets in two interfaces.
The reason is
ICMP Inspect seq num not matched (inspect-icmp-seq-num-not-matched)
The source is a VIP of some servers and the dest are some vpn clients.
In the logs of ASA I see the following
4|||313004|||||Denied ICMP type=0, from laddr <VIP> on interface <name> to <VPN Client>: no matching session
I have seen some bugs about the inspection
CSCvb92417 but the version is too old
Any ideas?
Thanks and regards,
Konstantinos
07-05-2021 05:46 AM
VPN client is RAVPN or S2S ?
07-05-2021 06:56 AM
RA VPN
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide