cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4368
Views
0
Helpful
7
Replies

ASA Hardware Acceleration Error

smulhollen
Level 1
Level 1

I get the following error on an ASA 5510 after Phase 1 and 2 complete successfully:

%ASA-4-402123: CRYPTO: The ASA hardware accelerator encountered an error (Invalid

IPSec Padding, code= 0x16) while executing the command Process IPSec Inbound Packet (0x30).

The other end of the L2L tunnel is a Cisco 7200VXR

Thanks.

7 Replies 7

zubairjalal
Level 1
Level 1

This is what Cisco says

Error Message %PIX|ASA-4-402123: CRYPTO: The accel_type hardware accelerator

encountered an error (code= error_string) while executing crypto command command .

accel_type?Hardware accelerator type

error_string?Code indicating the type of error

command?Crypto command that generated the error

Explanation This message is displayed when an error is detected while running a crypto command with a hardware accelerator. This could indicate a problem with the accelerator. This type of error may occur for a variety of reasons, and this message supplements the crypto accelerator counters to help determine the cause.

Recommended Action : Contact Cisco TAC for assistance.

http://www.cisco.com/en/US/products/ps6120/products_system_message_guide_chapter09186a008055fd2b.html#wp3110883

Thanks for the reply. I have already opened a TAC case, just thought someone may have seen this error before and had a fix.

Do you have any answer from the TAC? I have the same problem with ASA version 8.2(2)17. The difference is that I don't have any VPN configuration (except the defaults).

Martin - the issue in my case was with a VPN accelerator card in our VPN router which was terminating the IPSEC tunnel from the ASA.  The older ISA card was replaced with a VAMII+ card in the Cisco router and that solved the problem.  There was no real issue with the ASA, more of a compatability problem with an older Cisco VPN card.  Sounds unrelated to your problem

Martin,

I posted an update for this issue.

Sam

Sam

Thanks for the information. You are right, it's not the same problem(only the same error ID

%ASA-4-402123 ). In my setup I don't have any IPSec configuration and my errore message is the following.

%ASA-4-402123: CRYPTO: The ASA hardware accelerator encountered an error (Invalid PKCS Type, Pad, or Length, code= 0x1B) while executing the command SSL RSA Server Finish (return encrypted master secret) (0x6085).

Do you have any information about cause of this error message? I have also opened a TAC case with our integrator.

Regards,

Martin

Martin,

I haven’t seen that particular error, but best of luck getting it solved.

Sam