12-18-2010 05:01 AM
We have a cisco asa 5520, it gives a message (asdm syslog) that there is a functional problem with the hardware crypto chip.
Can this affect site-2-site vpn connections (ipsec)?
Kind Regards,
12-18-2010 09:08 AM
Hi,
If there's a hardware problem with the ASA it can affect not only the VPN but the entire device.
Can you share the exact log/message that you're seeing?
Federico.
12-18-2010 10:06 AM
Thank you for your reply,
the message is,
CRYPTO: The ASA is skipping the writing of latest Crypto Archive File as the maximum # of files ( 2 ) allowed have been written to < disk0:/crypto_archive >. Please archive & remove files from < disk0:/crypto_archive > if you want more Crypto Archive Files saved
the above message is appearing in de asdm syslog and have a sysid: 402127
As explanation is given:
There was a functional problem detected with the hardware crypto chip (see syslog messages 4402124/4402125). To further debug the crypto problem, a crypto archive file is generated, containing the current crypto hardware environment (hardware registers, Crypto Desc Entries, and so on). At boot time, a crypto_archive directory is automatically created on the flash file system (if it did not exist previously). A maximum of two crypto archive files are allowed to exist in this directory.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide