IPSEC problems after upgrade to 8.0(3)

Unanswered Question
Dec 4th, 2007
User Badges:

Hi,


After upgrading my asa devices (2*5510) I started to getting odd messages which relate to lan-to-lan connection between these:


Dec 4 03:18:15 stasa1 %ASA-3-713227: IP = A.B.C.D, Rejecting new IPSec SA negotiation for peer D.C.B.A. A negotiation was already in progress for local

Proxy x.x.x.x/x.x.x.x, remote Proxy x.x.x.x/x.x.x.x

Dec 4 03:18:15 stasa1 %ASA-3-713902: Group = A.B.C.D, IP = A.B.C.D, QM FSM error (P2 struct &0xd8c23fc8, mess id 0x132546bb)!

Dec 4 03:18:15 stasa1 %ASA-3-713902: Group = A.B.C.D, IP = A.B.C.D, Removing peer from correlator table failed, no match!


At same time, users complain that their connections were reset. I think that there were no problems when we were running 7.3.


I wonder if there is something in the configuration I'll have to change after upgrade ?

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
ciscovertis Tue, 12/04/2007 - 13:59
User Badges:

Hi,


I just solved the problem after forcing a failover to our secondairy asa.

Actions

This Discussion