cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
21614
Views
0
Helpful
7
Replies

What exactly causes "Removing peer from peer table failed, no match" on ASA

fortis123
Level 1
Level 1

Hello,

ASA1 <--> ASA2 VPN tunnel stable, works fine. One end has Internet issues and once resolved, the L2L tunnel took some time to establish. ASAs logging messages, "Removing peer from peer table failed, no match!". What exactly cause this issue ?

Thank you

MS

7 Replies 7

andrew.prince
Level 10
Level 10

Basically it means 1 of 2 things:-

1) You have lan2lan peers config - and a remote IP address is trying to connec, that you have not configured

2) A remote VPN client session is trying to connect - and you have not configured the remote dynamic VPN

HTH>

Hi Andrew,

Thanks for the reply.. but the l2L VPN has been in place from long time. The issue was observerved only when the interent has issues for some time recovered. IPs are inplace.

Nothing to do with Remote client session.

Thanks

MS

same problem here b/n ASA and 1841s in hub/spokes config, caused by power or Internet outages.

I reestablish the connection via "clear crypto ipsec sa" command on the hub (ASA 5510), but I did not find a cause yet

Have you found a cause for this? I've seen the same too in a very similar setup.

darthnul
Level 1
Level 1

This is pretty much a generic log that occurs after an IPSEC negotiation fails for just about any reason. Turn on debugging and look at the messages preceding this to find out why that particular negotiation failed. This message is generated by the cleanup routine that follows a failed negotiation. It can't find an entry in the table because the negotiation failed before it put an entry in the table.

I second this!

Patrick0711
Level 3
Level 3

Run 'debug crypto isak 254' to find out what triggered this event.

Or configure a logging list to just capture vpn debugging messages.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: