ASA VPN error: removing peer from correlator table failed, no match!
user got disconnected and no luck in reconnecting back until 10 minutes later,
ASA syslog shows : removing peer from correlator table failed, no match!
googled the error message, "Most Common L2L and Remote Access IPsec VPN Troubleshooting Solutions" mention this:
VPN tunnel fails to come up after moving configuration from PIX to ASA using the PIX/ASA configuration migration tool; these messages appear in the log:
[IKEv1]: Group = x.x.x.x, IP = x.x.x.x, Stale PeerTblEntry found, removing! [IKEv1]: Group = x.x.x.x, IP = x.x.x.x, Removing peer from correlator table failed, no match! [IKEv1]: Group = x.x.x.x, IP = x.x.x.x, construct_ipsec_delete(): No SPI to identify Phase 2 SA! [IKEv1]: Group = x.x.x.x, IP = x.x.x.x, Removing peer from correlator table failed, no match!
This issue happens since PIX by default is set to identify the connection as hostname where the ASA identifies as IP. In order to resolve this issue, use the crypto isakmp identity command in global configuration mode as shown below:
crypto isakmp identity hostname
my question is:
1. why the user got disconnected and was able to reconnect back in 10 minutes without any modification being done on ASA?
2. what does the log error mean? if similar issue happens again, should we take action at all?
Border handoff enhancements: 4-byte ASNEmbedded wireless support on Fabric edgeFiaB deployment models:Multiple VN for Guest Access in Cisco SD-AccessCisco SD-Access Group-Based Access Control PolicyBonjour support for Cisco SD-AccessCisco SD-Access APIs
. My work contains abbundance of networking gear.i have 3945 routers with attatched nme,3850 switches 48 gig port with 4 tengig port,3850 switch with 16 fiber ports, fortigate 600d along with servers with 8tbs of free space.if you have any labs for me id ...
Hello I have a network in prodcution like it mensionned in this picture. The customer wants to renovate the current infrastructure by changing all the hardware. For this reason we had think about deploying DNA Center and make automat...
I want to show how to quickly and reliably troubleshoot a network using notepad++.If you are not using Cisco GENIE and your network is not very big and you have several routers/switches only.For illustration, I created a simple topology.First, the loopbac...
Join us on Tuesday, October 15 at 10:00 am PT to to learn how Equinix and Cisco enable multicloud and Hybrid IT access.
Digital transformation initiatives are driving the adoption of internet, cloud, mobile and IoT technologies. In order t...