cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1558
Views
30
Helpful
1
Replies

ASA won't become full with ISR 4400 router

Garry Cross
Level 1
Level 1

I wanted to post this so it might be useful to someone else who is facing this issue.

Customer has a Juniper, not sure the model, working fine with a Cisco ASA5515. Project is to replace the Juniper with an ISR 4451. When replaced the ISR would not become full with the ASA.

Show ip ospf nei on the ISR shows the ASA in Init/dr other state. Show ospf neigh on the ASA shows nothing. The access applied on the interface to the ISR has permit ip any any and the only ACE prior is also a permit. Regardless the ISR and Juniper are using the same ip address. Running debugs on the ISR does not lead to any conclusions. I did not run debug on the ASA as it has production on it and too many messages. I did a packet capture with acl permit ip any host 224.0.0.5. The capture file show hellos from the router and hellos from the ASA. Saved the file and opened it in wireshark. ISR has the ASA listed in its hello but the ASA does not have the ISR listed in its hello. Further inspection of the packet from the ISR shows that it contains an LLS data block with what Wireshark calls an unknown LLS TLV. The TLV type is 32768, length 8, data 0x0000000900000027. 

So I do a search on ospf LLS and asa and find bug CSCvg78868.

Ok, so I add the following to the interface config on the ISR.

 

ip ospf lls disable

 

Low and behold problem solved.

1 Reply 1

Richard Burts
Hall of Fame
Hall of Fame

Thanks for posting this and informing readers of the forum about the issue and how you solved it. This kind of thing is very helpful. So +5 for you

 

HTH

 

Rick

HTH

Rick