cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
548
Views
0
Helpful
1
Replies

IPSEC problems after upgrade to 8.0(3)

ciscovertis
Level 1
Level 1

Hi,

After upgrading my asa devices (2*5510) I started to getting odd messages which relate to lan-to-lan connection between these:

Dec 4 03:18:15 stasa1 %ASA-3-713227: IP = A.B.C.D, Rejecting new IPSec SA negotiation for peer D.C.B.A. A negotiation was already in progress for local

Proxy x.x.x.x/x.x.x.x, remote Proxy x.x.x.x/x.x.x.x

Dec 4 03:18:15 stasa1 %ASA-3-713902: Group = A.B.C.D, IP = A.B.C.D, QM FSM error (P2 struct &0xd8c23fc8, mess id 0x132546bb)!

Dec 4 03:18:15 stasa1 %ASA-3-713902: Group = A.B.C.D, IP = A.B.C.D, Removing peer from correlator table failed, no match!

At same time, users complain that their connections were reset. I think that there were no problems when we were running 7.3.

I wonder if there is something in the configuration I'll have to change after upgrade ?

1 Reply 1

ciscovertis
Level 1
Level 1

Hi,

I just solved the problem after forcing a failover to our secondairy asa.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card