cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1206
Views
3
Helpful
1
Replies

TLS Error in ASA-SSM IPS Module

kiran.raj1
Level 1
Level 1

Hi All,

  I am encountering an error in ASA-SSM module as as "WebSession::sessionTask TLS connection exception: handshake incomplete. Messages, like this one, in the category - TLS connection failure - were logged 7 times in the last 249621 seconds."  Attaches Screenshot tells you in detail..

Also, i am not receiving any events on the sensor..Let me know how to resolve this issue..

Thanks in advance..

Regards

Kiran

1 Reply 1

Farrukh Haroon
VIP Alumni
VIP Alumni

Hello Kiran

This error usually comes when some device is trying to connect the sensor using an incorrect certificate.

This is an old post from one of th Cisco Guru's (Marco) on this subject, use this to pin-point the device causing this:

"That message is common when something is connecting to the sensor through HTTPS but is using the wrong TLS certificate.

However, this message does not let you know which box is having this connection problem.

If you are able to connect in from IDM and IDM is working fine, then it is likely that it is not IDM that is causing the errors.

More  than likely there is another box (or application) on your network that  is trying to connect and still has the old SSL certificate of the  sensor.

That Other box needs to be updated with the sensor's newest SSL certificate.

To  figure out the IP address of the Other box you could try and use the  "packet display" command on the sensor's command and control IP Address  to look for HTTPS sessions to the sensor that are short lived.

My  best guess is that you may have an old installation of IEV or some  other monitoring tool that is trying to connect to the sensor using an  old SSL certificate, and that application needs to be updated to use the  sensor's newest SSL certificate.

If  you can't connect in from IDM, and during those attempts you keep  getting that error.  Then your web browser has the old certificate  cached, and you need to get your browser to accept the newest SSL  certificate from your sensor.  IDM should then start working and the  error would go away."

Regards

Farrukh

Review Cisco Networking for a $25 gift card