09-30-2015 06:50 AM
Hi All,
Does any one have an permanent fix for this issue? One of customer VPN connections suddenly stops the traffic and connection is lost. This is becoming an regular issue and would need an permanent fix immediately. My current firewall ISO is ASA Version 9.1(6)
Issue :
Stale VPN Context entries cause ASA to stop encrypting traffic
ASAs which had a working L2L VPN tunnel suddenly stops encrypting traffic.
The ASP table will show duplicate ASP entries and traffic is hitting an ASP entry
that is stale and the traffic for particular SA is blackholed.
09-30-2015 09:38 AM
have you tried and disabled the data based rekey?
06-20-2017 12:04 PM
Did you ever find a permanent solution for this issue? I have a 5540 ASA code 9.1(7.16) that is experiencing duplicate sa entries in the asp tables. The only thing I can do is run the "clear crypto ipsec sa inactive" cmd to clear the duplicate sa.
12-23-2017 11:02 AM
Hi Praveen,
Cisco still don't have release for fixing this issue. I have resolved the issue by failing over to the Standby device then reloaded the primary one.
You can check the below bug search from Cisco
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCve94917/?reffering_site=dumpcr
Regards,
Anumod
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide