Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

EZVPN connection failing with error "Split tunnel attributes greater than max ..."

Hi,

We have ASA 5520 acting as the VPN Server and Cisco 1941 router as EZVPN client. Since last few days client is not able to establish vpn connection. 1941 router is continuously generating the below log messages

---------------

001569: Jul 22 12:19:05.883 ABC: %CRYPTO-4-EZVPN_SA_LIMIT: EZVPN(VPNGROUP) Split tunnel attributes(51) greater than max allowed split attributes(50)

001574: Jul 22 12:19:07.835 ABC: %CRYPTO-6-EZVPN_CONNECTION_DOWN: (Client)  User=vpn_user  Group=VPNGROUP Client_public_addr=<client public ip>  Server_public_addr=<server public ip>

004943: Jul 22 11:32:42.247 ABC: %IP_VFR-4-FRAG_TABLE_OVERFLOW: Dialer1: the fragment table has reached its maximum threshold 16

---------------

Looking forward for experts suggestion and help

Thanks,

Israr Ahmad

1 ACCEPTED SOLUTION

Accepted Solutions
Super Bronze

EZVPN connection failing with error "Split tunnel attributes gre

Yes, your split tunnel access-list is too large, and it has reached the maximum allowed number of line.

Try to reduce the number of ACL for your split tunnel ACL maybe by combining the subnets if possible.

3 REPLIES
Super Bronze

EZVPN connection failing with error "Split tunnel attributes gre

Yes, your split tunnel access-list is too large, and it has reached the maximum allowed number of line.

Try to reduce the number of ACL for your split tunnel ACL maybe by combining the subnets if possible.

EZVPN connection failing with error "Split tunnel attributes gre

Error Message    %CRYPTO-4-EZVPN_SA_LIMIT: [chars] 

Explanation    The maximum number of EZVPN tunnels that can be set up on the platform has been  reached. Active SAs will not be terminated, but additional SAs can not be established until the  number of existing SAs decreases.

So you have make SA's to get reduced.

Please do rate if the given information helps.

By

Karthik

New Member

EZVPN connection failing with error "Split tunnel attributes gre

Thanks Jennifer, That was spot on ... So in brief split tunnel access list can have only 50 entries.

--------

Thanks

Israr Ahmad

544
Views
0
Helpful
3
Replies