03-26-2020 03:39 AM
Hi All,
We are using Anyconnect SSL vpn in our setup. But as the number of session are increasing, it starts dropping at the firewall. When we debugged the asp drops it shows
ctm-error.
Attaching the log for reference. Check the connection between 182.64.73.214 > 196.1.111.161 > port 443
CTM returned error: ( as per information available on Cisco )
This counter will increment when the appliance attempts to perform a crypto operation on a packet and the crypto operation fails. This is not a normal condition and could indicate possible software or hardware problems with the appliance.
Please help in debugging the issue.
Thanks
03-26-2020 04:32 AM
Hi,
How many such drops do you have, look at "show asp drop". You could also hit some bugs, like this one for example. What software version are you using on the ASA? I would recommend to upgrade to 9.8.4 (latest interim version) or 9.12.3 (latest interim version), reload and see if you still get such messages.
Regards,
Cristian Matei.
03-26-2020 05:33 AM
03-26-2020 07:00 AM
03-26-2020 08:59 AM
Hi,
If the session doesn't get disconnected, there are only some drops on the ASA side, i don't see how DART could be useful. Upgrade and let's see the upcoming behaviour.
Regards,
Cristian Matei.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide