cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
952
Views
0
Helpful
3
Replies

EZVPN connection failing with error "Split tunnel attributes greater than max ..."

israr.ahmad
Level 1
Level 1

Hi,

We have ASA 5520 acting as the VPN Server and Cisco 1941 router as EZVPN client. Since last few days client is not able to establish vpn connection. 1941 router is continuously generating the below log messages

---------------

001569: Jul 22 12:19:05.883 ABC: %CRYPTO-4-EZVPN_SA_LIMIT: EZVPN(VPNGROUP) Split tunnel attributes(51) greater than max allowed split attributes(50)

001574: Jul 22 12:19:07.835 ABC: %CRYPTO-6-EZVPN_CONNECTION_DOWN: (Client)  User=vpn_user  Group=VPNGROUP Client_public_addr=<client public ip>  Server_public_addr=<server public ip>

004943: Jul 22 11:32:42.247 ABC: %IP_VFR-4-FRAG_TABLE_OVERFLOW: Dialer1: the fragment table has reached its maximum threshold 16

---------------

Looking forward for experts suggestion and help

Thanks,

Israr Ahmad

1 Accepted Solution

Accepted Solutions

Jennifer Halim
Cisco Employee
Cisco Employee

Yes, your split tunnel access-list is too large, and it has reached the maximum allowed number of line.

Try to reduce the number of ACL for your split tunnel ACL maybe by combining the subnets if possible.

View solution in original post

3 Replies 3

Jennifer Halim
Cisco Employee
Cisco Employee

Yes, your split tunnel access-list is too large, and it has reached the maximum allowed number of line.

Try to reduce the number of ACL for your split tunnel ACL maybe by combining the subnets if possible.

Error Message    %CRYPTO-4-EZVPN_SA_LIMIT: [chars] 

Explanation    The maximum number of EZVPN tunnels that can be set up on the platform has been  reached. Active SAs will not be terminated, but additional SAs can not be established until the  number of existing SAs decreases.

So you have make SA's to get reduced.

Please do rate if the given information helps.

By

Karthik

Thanks Jennifer, That was spot on ... So in brief split tunnel access list can have only 50 entries.

--------

Thanks

Israr Ahmad