cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4111
Views
0
Helpful
2
Replies

hardware crypto chip

bj_vosman
Level 1
Level 1

We have a cisco asa 5520, it gives a message (asdm syslog) that there is a functional problem with the hardware crypto chip.

Can this affect site-2-site vpn connections (ipsec)?

Kind Regards,

2 Replies 2

Hi,

If there's a hardware problem with the ASA it can affect not only the VPN but the entire device.

Can you share the exact log/message that you're seeing?

Federico.

Thank you for your reply,

the message is,

CRYPTO: The ASA is skipping the writing of latest Crypto Archive File as the maximum # of files ( 2 ) allowed have been written to < disk0:/crypto_archive >. Please archive & remove files from < disk0:/crypto_archive > if you want more Crypto Archive Files saved

the above message is appearing in de asdm syslog and have a sysid: 402127

As explanation is given:

There was a functional problem detected with the hardware crypto chip (see syslog messages 4402124/4402125). To further debug the crypto problem, a crypto archive file is generated, containing the current crypto hardware environment (hardware registers, Crypto Desc Entries, and so on). At boot time, a crypto_archive directory is automatically created on the flash file system (if it did not exist previously). A maximum of two crypto archive files are allowed to exist in this directory.