01-22-2009 05:56 AM
Hello,
ASA1 <--> ASA2 VPN tunnel stable, works fine. One end has Internet issues and once resolved, the L2L tunnel took some time to establish. ASAs logging messages, "Removing peer from peer table failed, no match!". What exactly cause this issue ?
Thank you
MS
01-22-2009 07:16 AM
Basically it means 1 of 2 things:-
1) You have lan2lan peers config - and a remote IP address is trying to connec, that you have not configured
2) A remote VPN client session is trying to connect - and you have not configured the remote dynamic VPN
HTH>
01-23-2009 11:49 AM
Hi Andrew,
Thanks for the reply.. but the l2L VPN has been in place from long time. The issue was observerved only when the interent has issues for some time recovered. IPs are inplace.
Nothing to do with Remote client session.
Thanks
MS
01-23-2009 01:44 PM
same problem here b/n ASA and 1841s in hub/spokes config, caused by power or Internet outages.
I reestablish the connection via "clear crypto ipsec sa" command on the hub (ASA 5510), but I did not find a cause yet
11-02-2009 03:04 PM
Have you found a cause for this? I've seen the same too in a very similar setup.
11-02-2009 04:57 PM
This is pretty much a generic log that occurs after an IPSEC negotiation fails for just about any reason. Turn on debugging and look at the messages preceding this to find out why that particular negotiation failed. This message is generated by the cleanup routine that follows a failed negotiation. It can't find an entry in the table because the negotiation failed before it put an entry in the table.
11-02-2009 05:41 PM
I second this!
11-02-2009 08:26 PM
Run 'debug crypto isak 254' to find out what triggered this event.
Or configure a logging list to just capture vpn debugging messages.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide