cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
32037
Views
0
Helpful
2
Replies

%ASA-vpn-4-713903:"IP address" Header invalid, missing SA payload!

logan-7
Level 1
Level 1

getting the error message %ASA-vpn-4-713903: IP = x.x.x.x, Header invalid, missing SA payload! (next payload = 4)

on a VPN tunnel initiation, this is the first time this tunnel has tried to connect and we are seeing this issue.

Any Ideas. Thanks

2 Replies 2

owillins
Level 6
Level 6

This event generally means that the VPN and the remote peer are out of sync. The remote peer is continuing to negotiate an Internet Key Exchange (IKE) Security Association (SA) that has been deleted by the VPN Device. The condition should eventually correct itself as the negotiation times out. This event can sometimes indicate a begin condition, which is caused by a race condition. An example of a race condition is when both peers delete an SA simultaneously and send deletes. The delete messages get to the peer, but the peer has already deleted the SA on its own. The peer expects a new phase 1 message to include an SA payload, which the delete message does not include.

If the condition persists, the tunnel should be reset on both sides.

Farrukh Haroon
VIP Alumni
VIP Alumni

As others have pointed out, these messages can be displayed even if everything is working fine. Clear the IKE/IPSEC sessions on both sides and then see if there is reasonable uniformity between the encryp/decypt packet count (show crypto ipsec sa). If so, ignore this error.

Regards

Farrukh

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card