cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
606
Views
0
Helpful
0
Replies

ASA-2-106016: Deny IP spoof from (<Remote Office IP>(<Remote ASA>)) to <Remote Office IP>(<Remote ASA>) on interface outside

stownsend
Level 2
Level 2

I have a Remote office (1 of 10) that is getting its VPN Disconnected from time to time. In my Syslogs for all 10 Sites, out of 3677 ASA-2-106016 Syslog messages, 3645 of them are this one remote office with the Following:

%ASA-2-106016: Deny IP spoof from (<Remote Office IP>(<Remote ASA>)) to <Remote Office IP>(<Remote ASA>) on interface outside

I don't see any other suspicious activity at this site, so I'm not sure if its really someone on the outside spoofing the External IP of if its something to do with why the VPN does not seem to be very stable. 

Remote end is using ASA5505 8.3(2) (yes I need to upgrade it, though it is at a non IT Staffed Location) though So are several other Remote sites. 

This has been happening with Head End on a 5510 8.3(2) and still after upgrading to a 5525-x 9.4(1)

 

Any Suggestions?

0 Replies 0