cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
980
Views
0
Helpful
3
Replies

UC560 SSL VPN with CCA 3 Problem

John Shen
Level 1
Level 1

Hi,

I have a customer has a UC560, for some reason the unit lost part of its VPN and SSL VPN configuration.

The CCA does not want to go into SSL configuration - it keep asking to delete some of the configurations, and the VPN (IPSec part) is always giving a java error.

I manually copied the configuration into the CLI, the only difference is the self signed certifcate is somehow different (The last 20 numbers), and I still can't get the VPN to work.

I'd love to use CCA to configure it, but it won't allow me - what can I do? Please help. Thanks!

John

Before

crypto pki certificate chain TP-self-signed-2012409281

certificate self-signed 01

  30820243 308201AC A0030201 02020101 300D0609 2A864886 F70D0101 04050030

  31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274

  69666963 6174652D 32303132 34303932 3831301E 170D3131 30343239 31353330

  34355A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649

  4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D32 30313234

  30393238 3130819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281

  8100A030 A0A98F5D 4353AEB7 C51A1836 C9E3F435 E871CC86 2207AFCC 3A459F1F

  689C0AE2 64295E13 F8CE5E88 6C8A9E9E 41666E59 72135DA7 82C26FEC A20BC6D0

  0805D33A F9ADFB9B F877620E CBB68ABB 25F66393 3E31780A 1E61D5FF 0AAAB6A3

  490A49D4 05DFB53B 00B7F9CD 27C2D865 DAD5FC18 1B4D1F5F F9283482 CC6C49ED

  16110203 010001A3 6B306930 0F060355 1D130101 FF040530 030101FF 30160603

  551D1104 0F300D82 0B417370 6972612D 564F4950 301F0603 551D2304 18301680

  141E4919 D0337A46 68FCDB2E FFD5CE39 12F829B9 35301D06 03551D0E 04160414

  1E4919D0 337A4668 FCDB2EFF D5CE3912 F829B935 300D0609 2A864886 F70D0101

  04050003 8181003A 14180296 9CFECA0B 70AB166F 52C50C10 53267B65 C81F6E83

  8D1EB95D BBF58DB5 FF415014 5F91B79A BEDB1507 8F1C3BDF 7972900A 304FCCF2

  34FC8278 409B5C03 93C9E690 C0BA8AD0 87E64692 ED2BD735 88B2BA8D FB97D8C3

  DD50BA6C DF003081 EB6EFF80 07C214BD 664F9966 87282C73 8BB0259D 6E751AE8

  2A56A6D8 B7A408

   quit

After

crypto pki certificate chain TP-self-signed-2012409281

certificate self-signed 01

  30820243 308201AC A0030201 02020101 300D0609 2A864886 F70D0101 04050030

  31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274

  69666963 6174652D 32303132 34303932 3831301E 170D3131 30383130 31393436

  32345A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649

  4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D32 30313234

  30393238 3130819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281

  8100A030 A0A98F5D 4353AEB7 C51A1836 C9E3F435 E871CC86 2207AFCC 3A459F1F

  689C0AE2 64295E13 F8CE5E88 6C8A9E9E 41666E59 72135DA7 82C26FEC A20BC6D0

  0805D33A F9ADFB9B F877620E CBB68ABB 25F66393 3E31780A 1E61D5FF 0AAAB6A3

  490A49D4 05DFB53B 00B7F9CD 27C2D865 DAD5FC18 1B4D1F5F F9283482 CC6C49ED

  16110203 010001A3 6B306930 0F060355 1D130101 FF040530 030101FF 30160603

  551D1104 0F300D82 0B417370 6972612D 564F4950 301F0603 551D2304 18301680

  141E4919 D0337A46 68FCDB2E FFD5CE39 12F829B9 35301D06 03551D0E 04160414

  1E4919D0 337A4668 FCDB2EFF D5CE3912 F829B935 300D0609 2A864886 F70D0101

  04050003 81810094 EF88A55F 4A96EF18 810BE1DE B64FAE3D F6513DD9 D1119804

  325D14E8 54445DF2 5883F17B 91FDAE92 C13CB54D 11F3D0B0 4DC17631 DA6522ED

  7CE94525 83AB0291 ECA91590 6154E7AD CBF4F6FF 6BE4AA60 517E76FA 316A1ACE

  1D36018F 6D636595 EFEC6174 F4224F1A C1895E55 8672FD99 F51A96C8 0677B447

  4E83B11C 568668

        quit

dot11 syslog

crypto pki certificate chain TP-self-signed-2012409281

certificate self-signed 01

  30820243 308201AC A0030201 02020101 300D0609 2A864886 F70D0101 04050030

  31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274

  69666963 6174652D 32303132 34303932 3831301E 170D3131 30383130 31393436

  32345A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649

  4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D32 30313234

  30393238 3130819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281

  8100A030 A0A98F5D 4353AEB7 C51A1836 C9E3F435 E871CC86 2207AFCC 3A459F1F

  689C0AE2 64295E13 F8CE5E88 6C8A9E9E 41666E59 72135DA7 82C26FEC A20BC6D0

  0805D33A F9ADFB9B F877620E CBB68ABB 25F66393 3E31780A 1E61D5FF 0AAAB6A3

  490A49D4 05DFB53B 00B7F9CD 27C2D865 DAD5FC18 1B4D1F5F F9283482 CC6C49ED

  16110203 010001A3 6B306930 0F060355 1D130101 FF040530 030101FF 30160603

  551D1104 0F300D82 0B417370 6972612D 564F4950 301F0603 551D2304 18301680

  141E4919 D0337A46 68FCDB2E FFD5CE39 12F829B9 35301D06 03551D0E 04160414

  1E4919D0 337A4668 FCDB2EFF D5CE3912 F829B935 300D0609 2A864886 F70D0101

  04050003 81810094 EF88A55F 4A96EF18 810BE1DE B64FAE3D F6513DD9 D1119804

  325D14E8 54445DF2 5883F17B 91FDAE92 C13CB54D 11F3D0B0 4DC17631 DA6522ED

  7CE94525 83AB0291 ECA91590 6154E7AD CBF4F6FF 6BE4AA60 517E76FA 316A1ACE

  1D36018F 6D636595 EFEC6174 F4224F1A C1895E55 8672FD99 F51A96C8 0677B447

  4E83B11C 568668

        quit

dot11 syslog

3 Replies 3

David Trad
VIP Alumni
VIP Alumni

Hi John,

Quick couple of questions... Have you upgraded CCA to the latest version? The latest version 3.1 is much more stable than version 3.0.1.

Also have you upgraded the system to the latest Software Pack? If this is an option and you can do it, can you do that as well??

Lastly can you please take a screen shot of the error and also post the CCA log files of the same day the issue happened, these logs can be found in program files under the Cisco Systems folder and then CCA's directory.

Cheers,

David.

Cheers, David Trad. **When you rate a persons post, you are indicating a thank you or that it helped, but at the same time you are also helping to maintain the community spirit - You don't have to rate posts and you wont be looked down upon :) *

Hi, David,

Thanks for the quick reply - I am upgrade to CCA 3.1 now. It's not an option for the upgrade yet. And I cannot get a screenshot for the errors. But they are generic - VPN server error is Java popup I am sure everyone got that before. And the SSL error it kept asking me to delete some of the configurations which were not configured by CCA...

As for log, I have a lot...I was there for two hours, so the attached are log files...wait, how do I attach files?

Hi John,

As for log, I have a lot...I was there for two hours, so the attached are log files...wait, how do I attach files?

Just above where it says "abc" and "HTML" there is an "Use advance editor"  hyperlink, use this and you can then attache files

or

In the top navigation bar near the numbering and bullet point section there is two icons, one of a camera and one of a video, you can use the camera one to insert it directly into the post instead of just an attachment

What are the chances of giving me a remote desktop session to your computer so we can both look at it, I am certain this can be resolved with CCA.

Cheers,

David.

Cheers, David Trad. **When you rate a persons post, you are indicating a thank you or that it helped, but at the same time you are also helping to maintain the community spirit - You don't have to rate posts and you wont be looked down upon :) *
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: