cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
457
Views
0
Helpful
1
Replies

ipsec tunnel problem works without configuration on asa

lbellicaud
Level 1
Level 1

Hi everyone,

I have a problem with one asa version 8.4.3.

I have a tunnel that mount with a remote site if I did not configure the tunnel and if I configure it does not mount

someone you already see that? With version 8.2, we had no worries but since migration problem there.

With configuration tunnel we have this error:

IKEv1]: Group = x.x.x.x, IP = x.x.x.x, QM FSM error (P2 struct &0x49ba5a0, mess id 0xcd600011)!

[IKEv1]: Group = x.x.x.x, IP = x.x.x.x, Removing peer from correlator table failed, no match!

Thanks for your response

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

I've never seen that as the result of a simple ASA upgrade but in general there are a couple of things that could cause this issue. Generally it is an unidentified peer or peer without valid crypto map trying to establish a site-site VPN that results in the above message.

Please have a look at this troubleshooting guide.

If that doesn't help. please post your script

View solution in original post

1 Reply 1

Marvin Rhoads
Hall of Fame
Hall of Fame

I've never seen that as the result of a simple ASA upgrade but in general there are a couple of things that could cause this issue. Generally it is an unidentified peer or peer without valid crypto map trying to establish a site-site VPN that results in the above message.

Please have a look at this troubleshooting guide.

If that doesn't help. please post your script