cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
889
Views
0
Helpful
1
Replies

Orphaned entries in show crypto session summary output

niedax_edv
Level 1
Level 1

Hello together,

we use a Cisco 2811 with IOS-Version 12.4(3a) and the Cisco VPN-Client Ver. 4.8.01 to connect our roadwarriors to our company network. Sometimes we have the folowing problem:

Maybe due to underlying network connection problems(umts-/gprs-interruption) the client disconnects, but nevertheless the output of the "show crypto session groups"-command displays one connection for this user. (We configured one group for every user.) But the "show crypto session detail"-command delivers no information about this client e.g. ip-adress. The User is not able to log in until an unspecified amount of time.

We configured the dead peer detection to solve the problem:

crypto isakmp keepalive 60 periodic

and the output of "debug crypto isakmp" attest that dpd works. But there are no "DPD/R_U_THERE"-messages between the client and the gateway. Everythings looks like the client isn't connected anymore besides the output of "show crypto session groups".

Any ideas?

Thanks for your help.

Regards, Stefan

1 Reply 1

wong34539
Level 6
Level 6

It looks like bug to me, check this bug-id: CSCsb08423.

Review Cisco Networking for a $25 gift card