×

Warning message

  • Cisco Support Forums is in Read Only mode while the site is being migrated.
  • Cisco Support Forums is in Read Only mode while the site is being migrated.

VPN Error

Answered Question
Oct 2nd, 2013
User Badges:
  • Silver, 250 points or more

I have setup a VPN on an ASA running 8.2 code.  Phase 1 and 2 pass, but when I look at the interesting traffic I see this?


7Oct 02 201314:56:30713222



Group = 63.x.x.96, IP = 63.x.x.200, Static Crypto Map check, map = Outside_map2, seq = 16, ACL does not match proxy IDs src:63.x.x.200 dst:10.202.90.12


I definitely have these lines in the config:


access-list Outside_cryptomap_36 extended permit ip host 10.202.90.12 host 63.x.x.200


crypto map Outside_map2 36 match address Outside_cryptomap_36


Any idea what else might be missing?

Correct Answer by Jeet Kumar about 3 years 10 months ago

Hi Mohammed,


Its actually not an error but an information message which is telling you that he checked crypto map Outside_map2 16 doest have the match for the interesting traffic which makes perfect sense because teh crypto map you are using is sequence number 36.


Just to let you know that while phase 2 is coming up he checks from the top (which means lower sequence number), and goes though the list of crypto map configured till the time he finds a map.


I hope that it answered your question.


Thanks

Jeet Kumar

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (2 ratings)
Loading.
Correct Answer
Jeet Kumar Wed, 10/02/2013 - 18:05
User Badges:
  • Cisco Employee,

Hi Mohammed,


Its actually not an error but an information message which is telling you that he checked crypto map Outside_map2 16 doest have the match for the interesting traffic which makes perfect sense because teh crypto map you are using is sequence number 36.


Just to let you know that while phase 2 is coming up he checks from the top (which means lower sequence number), and goes though the list of crypto map configured till the time he finds a map.


I hope that it answered your question.


Thanks

Jeet Kumar

Mohammad Ali Thu, 10/03/2013 - 09:05
User Badges:
  • Silver, 250 points or more

Ahhhhh I see, is this an 8.2 message? because I don't recall these on 8.4 firewalls and its been like over 2 years since I worked on a firewall running 8.2 code.


Thank you for your help.

Actions

This Discussion