cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
549
Views
0
Helpful
1
Replies

IPSEC problems after upgrade to 8.0(3)

ciscovertis
Level 1
Level 1

Hi,

After upgrading my asa devices (2*5510) I started to getting odd messages which relate to lan-to-lan connection between these:

Dec 4 03:18:15 stasa1 %ASA-3-713227: IP = A.B.C.D, Rejecting new IPSec SA negotiation for peer D.C.B.A. A negotiation was already in progress for local

Proxy x.x.x.x/x.x.x.x, remote Proxy x.x.x.x/x.x.x.x

Dec 4 03:18:15 stasa1 %ASA-3-713902: Group = A.B.C.D, IP = A.B.C.D, QM FSM error (P2 struct &0xd8c23fc8, mess id 0x132546bb)!

Dec 4 03:18:15 stasa1 %ASA-3-713902: Group = A.B.C.D, IP = A.B.C.D, Removing peer from correlator table failed, no match!

At same time, users complain that their connections were reset. I think that there were no problems when we were running 7.3.

I wonder if there is something in the configuration I'll have to change after upgrade ?

1 Reply 1

ciscovertis
Level 1
Level 1

Hi,

I just solved the problem after forcing a failover to our secondairy asa.

Review Cisco Networking products for a $25 gift card