VPN HW-1-PACKET ERROR

Hi all,
my customer is seen lots of errors shown below
%VPN_HW-1-PACKET_ERROR: slot: 2 Packet Encryption/Decryption error, Output Authentication error:srcadr=y.y.y.y,dstadr=x.x.x.x,size=1392,handle=0x5BA7
%VPN_HW-1-PACKET_ERROR: slot: 2 Packet Encryption/Decryption error, Output Authentication error:srcadr=y.y.y.y,dstadr==x.x.x.x,size=1392,handle=0x5BA7
%VPN_HW-1-PACKET_ERROR: slot: 2 Packet Encryption/Decryption error, Output Authentication error:srcadr=y.y.y.y,dstadr==x.x.x.x,size=1392,handle=0x5BA7
%VPN_HW-1-PACKET_ERROR: slot: 2 Packet Encryption/Decryption error, Output Authentication error:srcadr=y.y.y.y,dstadr=x.x.x.x,size=1392,handle=0x5AB0
%VPN_HW-1-PACKET_ERROR: slot: 2 Packet Encryption/Decryption error, ESP Pad Length:srcadr=y.y.y.y,dstadr=x.x.x.x,size=96,handle=0x5AB0
I have looked in to the show commands and could not see anything which points me to an issue
===============================================
router#show crypto eli
Hardware Encryption Layer :   ACTIVE
Number of crypto engines = 1 .
CryptoEngine-0 (slot-2) details.
Capability-IPSec : IPPCP, 3DES, AES, RSA
IKE-Session   :   229 active,  5120 max, 0 failed
DH-Key        :    12 active,  5120 max, 0 failed
IPSec-Session :  1034 active, 10230 max, 0 failed
router#Show pas vam interf
VPN Acceleration Module Version II+ in slot : 2
        Statistics for Hardware VPN Module since the last clear
         of counters 241663 seconds ago
      368408630 packets in                   368408630 packets out
   203515582983 bytes in                  202789234970 bytes out
           1524 paks/sec in                       1524 paks/sec out
           6737 Kbits/sec in                      6713 Kbits/sec out
              0 pkts compressed                      0 pkts not compressed
              0 bytes before compress                0 bytes after compress
          1.0:1 compression ratio                1.0:1 overall
        3981449 commands out                   3981449 commands acknowledged
        Last 5 minutes:
         935955 packets in                      935955 packets out
           3119 paks/sec in                       3119 paks/sec out
       13198000 bits/sec in                   13123845 bits/sec out
Errors:
   ppq full errors         :        0   ppq rx errors           :        5
   cmdq full errors        :        0   cmdq rx errors          :        0
   ppq down errors         :        0   cmdq down errors        :        0
   no buffer               :        0   replay errors           :      471
   dest overflow           :        0   authentication errors   :      252
   Other error             :        0   Raw Input Underrun      :        5
   IPSEC Unsupported Option:        0   IPV4 Header Length      :        0
   ESP Pad Length          :        5   IPSEC Decompression     :        0
   AH ESP seq mismatch     :        0   AH Header Length        :        0
   AH ICV Incorrect        :        0   IPCOMP CPI Mismatch     :        0
   IPSEC ESP Modulo        :        0   Unexpected IPV6 Extensio:        0
   Unexpected Protocol     :        0   Dest Buf overflow       :        0
   IPSEC Pkt is fragment   :        0   IPSEC Pkt src count     :        0
   Invalid IP Version      :        0   Unwrappable             :        0
   PPTP Duplicate packet   :        0   PPTP Exceed max missed p:        0
   RNG self test fail      :        0   DF Bit set              :        0
   Hash Miscompare         :        0   Unwrappable object      :        0
   Missing attribute       :        0   Invalid attrribute value:        0
   Bad Attribute           :        0   Verification Fail       :        0
   Decrypt Failure         :        0   Invalid Packet          :        0
   Invalid Key             :        0   Input Overrun           :        0
   Input Underrun          :        0   Output buffer overrun   :        0
   Bad handle value        :        0   Invalid parameter       :        0
   Bad function code       :        0   Out of handles          :        0
   Access denied           :        0   Out of memory           :        0
   NR overflow             :        0   pkts dropped            :      257
Warnings:
   sessions_expired        :        0   packets_fragmented      :        0
   general                 :        0   compress_bypassed       :        0
HSP details:
   hsp_operations          : 67829762   hsp_sessions            :     1258
Slot 2:
        VAM2+ Encryption/Compression engine, Port adapter
        Port adapter is analyzed
        Port adapter insertion time 6w3d ago
        EEPROM contents at hardware discovery:
        Hardware Revision        : 1.0
        PCB Serial Number        : AAAAAAAAAAAAA
        Part Number              : 73-9571-06
        Board Revision           : A0
        RMA Test History         : 00
        RMA Number               : 0-0-0-0
        RMA History              : 00
        Deviation Number         : 0
        Product (FRU) Number     : SA-VAM2+
        Version Identifier       : V02
        Top Assy. Part Number    : 68-2288-06
        CLEI Code                : CNDQASMGAA
        EEPROM format version 4
        EEPROM contents (hex):
          0x00: 04 FF 40 04 B0 41 01 00 C1 8B 4A 41 46 31 33 33
          0x10: 32 42 50 43 44 82 49 25 63 06 42 41 30 03 00 81
          0x20: 00 00 00 00 04 00 88 00 00 00 00 CB 94 53 41 2D
          0x30: 56 41 4D 32 2B 20 20 20 20 20 20 20 20 20 20 20
          0x40: 20 89 56 30 32 20 87 44 08 F0 06 C6 8A 43 4E 44
          0x50: 51 41 53 4D 47 41 41 FF FF FF FF FF FF FF FF FF
          0x60: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
          0x70: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
------------------ show pas isa interface ------------------
VPN Acceleration Module Version II+ in slot : 2
        Statistics for Hardware VPN Module since the last clear
         of counters 3204653 seconds ago
     6653099487 packets in                  6653099487 packets out
  3413929884758 bytes in                 3416877945028 bytes out
           2076 paks/sec in                       2076 paks/sec out
           8522 Kbits/sec in                      8529 Kbits/sec out
              0 pkts compressed                      0 pkts not compressed
              0 bytes before compress                0 bytes after compress
          1.0:1 compression ratio                1.0:1 overall
       51878047 commands out                  51878047 commands acknowledged
        Last 5 minutes:
         996655 packets in                      996655 packets out
           3322 paks/sec in                       3322 paks/sec out
       13649702 bits/sec in                   13570320 bits/sec out
Errors:
   ppq full errors         :        0   ppq rx errors           :       11
   cmdq full errors        :        0   cmdq rx errors          :        0
   ppq down errors         :        0   cmdq down errors        :        0
   no buffer               :        0   replay errors           :     5548
   dest overflow           :        0   authentication errors   :      872
   Other error             :        0   Raw Input Underrun      :       11
   IPSEC Unsupported Option:        0   IPV4 Header Length      :        0
   ESP Pad Length          :       11   IPSEC Decompression     :        0
   AH ESP seq mismatch     :        0   AH Header Length        :        0
   AH ICV Incorrect        :        0   IPCOMP CPI Mismatch     :        0
   IPSEC ESP Modulo        :        0   Unexpected IPV6 Extensio:        0
   Unexpected Protocol     :        0   Dest Buf overflow       :        0
   IPSEC Pkt is fragment   :        0   IPSEC Pkt src count     :        0
   Invalid IP Version      :        0   Unwrappable             :        0
   PPTP Duplicate packet   :        0   PPTP Exceed max missed p:        0
   RNG self test fail      :        0   DF Bit set              :        0
   Hash Miscompare         :        0   Unwrappable object      :        0
   Missing attribute       :        0   Invalid attrribute value:        0
   Bad Attribute           :        0   Verification Fail       :        0
   Decrypt Failure         :        0   Invalid Packet          :        0
   Invalid Key             :        0   Input Overrun           :        0
   Input Underrun          :        0   Output buffer overrun   :        0
   Bad handle value        :        0   Invalid parameter       :        0
   Bad function code       :        0   Out of handles          :        0
   Access denied           :        0   Out of memory           :        0
   NR overflow             :        0   pkts dropped            :      883
Warnings:
   sessions_expired        :        0   packets_fragmented      :        0
   general                 :        0   compress_bypassed       :        0
HSP details:
   hsp_operations          : 63582808   hsp_sessions            :     1270
------------------ show pas isa controller ------------------
Controller Information of Slot 2:
Encryption Mode = IPSec
Addresses of Rings and instance structure:
Low Priority Queue:
    OMQ=0xE3A4CC0, OMQ Shadow = 0x64B69FD8, {139, 139, 0, 256}
    PKQ=0xE3A8D00, PKQ Shadow = 0x64B6EC0C, {105, 105, 0, 256}
    ERQ=0xE3ACD40, ERQ Shadow = 0x64B73840, {0, 0, 0, 256}
Heartbeat info: <Addr, Value> = <0xE3B7EC0, 25CD87A>
Running default HSP (addr=0x63973630, size=809364)
hsp_version: 3.4(3) (PRODUCTION)
History Log location: 0x6464F9A0, end: 0x6465B520
High Priority Rings:
   TX:  0x0E3B0D80 {h=100, t=100, queued=0}
  SRC:  0x0E3B3640 TX Shadow: 0x64B78474, {h=196, t=196}
   RX:  0x0E3B1DC0 {100, 100, 256}
   RX Pool: 0x00000000 RX Pool(hsp): 0x0E3B2E00 RX Pool Shadow: 0x64B868A8, {255, 254, 511}
Instance Structure address: 0x64B63548, ce_id=0
Misc registers:
HIFN_REG=0x3D000000
IndexReg = 0xFFFF688A
PPQ registers:
 CMD  ring: ctl=0x18, head=0x64, tail=0x64 [0xE3B13C0, 0xE3B13C0]
 SRC  ring: ctl=0x10, head=0xC4, tail=0xC4 [0xE3B3C60, 0xE3B3C60]
 RSLT ring: ctl=0x5C, head=0x64, tail=0x64 [0xE3B2400]
 FREE ring: ctl=0x2000058, head=0x100, tail=0xFF [0xE3B3200]
PCI registers:
 pci_stat=0x60000, pci_intr_err_addr=0x0
hifn_driver_vary: 0x00000100
VAM2+ Active FLASH Image is: (V1) Default Image
Image Info for (V1) FLASH Default Image
Image Token == 0x2FADED2C: Image is Valid
Version        [0x03090002,0x03900201]
ChkSum    from [0xBFC00000,0xBFC2F618) is 0x00000000 with Comp==0x6C08F152
Image ChkSum is Valid
Image Info for (V2) FLASH Downloaded Image
Image Token == 0xFFFFFFFF: Image is NOT Valid
==========================================================
per Cisco error lookup, I need to escalate this to Cisco TAC, before I do that, does anyone has any idea what's causing it. My initial thoughts were HW issue
thanks in advance
Lance

any one? any idea?

Similar Messages

  • Communication packets error with MySQL

    Hi,
    I'm having a problem with executing a query on MySQL. It seems that I'm getting the communication packets error once in a while and I'm not sure whether the query is bad or the settings on the database server is bad. Could anyone give me an insight where to look after?
    Thank you,
    852825
    MySQL: 5.1.41-3ubuntu12.7
    JDBC: 5.1.12
    Caused by: com.mysql.jdbc.exceptions.jdbc4.MySQLNonTransientConnectionException: Got an error writing communication packets
         at sun.reflect.NativeConstructorAccessorImpl.newInstance0(Native Method)
         at sun.reflect.NativeConstructorAccessorImpl.newInstance(NativeConstructorAccessorImpl.java:57)
         at sun.reflect.DelegatingConstructorAccessorImpl.newInstance(DelegatingConstructorAccessorImpl.java:45)
         at java.lang.reflect.Constructor.newInstance(Constructor.java:532)
         at com.mysql.jdbc.Util.handleNewInstance(Util.java:409)
         at com.mysql.jdbc.Util.getInstance(Util.java:384)
         at com.mysql.jdbc.SQLError.createSQLException(SQLError.java:1015)
         at com.mysql.jdbc.MysqlIO.checkErrorPacket(MysqlIO.java:3562)
         at com.mysql.jdbc.MysqlIO.checkErrorPacket(MysqlIO.java:3494)
         at com.mysql.jdbc.MysqlIO.sendCommand(MysqlIO.java:1960)
         at com.mysql.jdbc.MysqlIO.sqlQueryDirect(MysqlIO.java:2114)
         at com.mysql.jdbc.ConnectionImpl.execSQL(ConnectionImpl.java:2696)
         at com.mysql.jdbc.PreparedStatement.executeInternal(PreparedStatement.java:2105)
         at com.mysql.jdbc.PreparedStatement.executeQuery(PreparedStatement.java:2264)

    I've tried the community but no response so far. Any tips on where to look?

  • WRP400: audio drops for 5..15 seconds on each packet error.

    Hi,
    On several calls i noticed that the outgoing audio stops for 5..15 seconds randomly.
    I'd say it happens on an average of every 5 minutes.
    When this happens, i can see that the value after "Call1 Packet error:" increases by one.
    Why just a wrong packet may stop the outgoing audio for so long?
    ...i've much more packet losts (about 3%) but they give me no problem at all.
    Since a little and cheaper Handytone HT502 gave me intermittent audio too, but the effect was much better (audio still stops, but in a second it comes back), i wonder if is there something i can do by tweaking the WRP400 settings, I'm still using firmware 1.01.00.
    Thanks.

    See this:
    http://www.cisco.com/en/US/docs/voice_ip_comm/csbpvga/wrp400/release/notes/WRP400_RN_v2-00-26.pdf
    Additional Provisioning Parameters
    Additional provisioning parameters were added for configuring router/data parameters via open (XML-style) format.
    NOTE
    A sample XML profile can be generated by using the profile compiler tool (SPC). For instructions about provisioning, see the WRP400 Administration Guide at the following URL: http://www.cisco.com/en/US/docs/voice_ip_comm/csbpvga/wrp400/administration/guide/WRP400_AG_OL-19688.pdf
    Two configurable and provisionable parameters are available to address an issue with voice cutoff. You can adjust the Soft IRQ for Voice settings to suit the deployment scenario.
    To configure these parameters, connect to the following URL: http://192.168.15.1/VoiceDebug.asp
    Use the syntax shown in the following example, and described below.
    Example:
    softirq_active_voice=0,softirq_polling_cnt=1
    Parameters:
    •softirq_active_voice: Enable or disable Soft IRQ for Voice. Valid values are 0 (disabled) and 1 (enabled)
    •softirq_polling_cnt: Specify the polling count. Valid values are integers from 0 to 10.
    After upgrade, default parameters fixed my cutoff issue.
    Regards.

  • VPN connection terminated, Smartcard Error - AnyConnect 3.1.03103

    Hello,
    we have upgradet our AnyConnect Client from V3.0.4235 to V3.1.03103. After the upgrade, I can me authenticate with RSA. After authentication, the AnyConnect will startup the connection but it failed with the error message "VPN connection terminated, Smartcard Error". We use the mashine certificate to encrypt the SSL-connection. We don't use smart cards. When I disable the smartcard reader (DELL Wireless 5540 HSPA Mini-Card USIM Port) in the device manager, the connection is established.
    In the version 3.0.08057 it works too. The error is only from verion 3.1.03103 and only on Windows 7 Prof. Under Win XP it works.
    How can I disable the query the smartcard?
    Thanks for help or answers.
    Daniel

    Hi Daniel,
    This is a known issue on systems with the Dell 5540, and 5550 card, Cisco bug ID is CSCue30862. You cannot disable querying of this card.  The fix for this issue is in the next release of AnyConnect.
    Thanks,
    Steve S.

  • Cannot install oracle vpn on linux getting error kernel-sourcecode is neede

    cannot install oracle vpn on linux getting error kernel-sourcecode is needed by gds_cisco_vpn_client-2.0-llrhel4.i386.. i already installed kernel-devel still it get the same error. pls help.

    1. kernel (.rpm)
    2. kernel-devel (.rpm) - containing only Makefiles and some kernel header files
    3. kernel source rpm (src.rpm) - source for rebuilding the kernel
    4. kernel-sourcecode (.rpm) - source-tree for developing custom kernels
    are four different packages.
    If you are running OEL-4 (2.6.9 kernel) and you have an ULN account, you can download kernel-sourcecode rpm from ULN. There is no kernel-sourcecode for OEL-5 available on ULN site.
    NJ

  • MARS - inbound packet error rate high for unrouted VLAN

    After upgrade to 4.2.2, we are getting lots of inbound packet error rate high for some unrouted vlan in Cisco 6509. I did some sniff and find that MARS try to get ifInErrors of those unrouted vlan. But the unrouted vlan only support ifOutUcastPkts and ifInUcastPkts.
    I just wondering is there some bug in the MARS or there are some kind of database corruption.

    Any reason you wouldn't just create a drop rule or modify the inspection rule that is firing?
    btw, have a look here to make sure it isn't the same issue:
    http://groups.google.com/group/cs-mars-ug/browse_thread/thread/9431fe079f7245ef/f4516dea991132da?lnk=gst&q=ingress&rnum=1#

  • Network packet error in MSSQL

    Hi Experts,
    Could you please suggest what could be done if a network packet error occured on a mssql server connection.
    Thanks and regards,
    Deepthi

    Retransmit the packet
    Seriously - what error are you seing?
    Markus

  • "Packet Error is in Overloaded state"

    I’m getting this error message on my WLSE. Can anyone help me with this?
    Thanks,

    I am also seeing the error message “Packet Error is in Degraded state” too. Do you think this is caused by the same bug?
    Thanks again,

  • Packet Errors?

    I just signed-up for ClearWire. So far, it's working great and much faster than my regular DSL (I had 768Mbps but now have 1.5Gbps). Because I live in an Apartment building where I can see eight other wireless networks, I have a WPA2 (Personal) password on my AirPort Express. I have the light enabled to display network activity and previously with the regular DSL, I used see some activity that I couldn't explain. Now with the ClearWire modem attached the activity light is going absolutely bonkers. It appears that I'm downloading constantly even if I turn AirPort off all the computers here. I can check with the AirPort Management Utility and it appears that only my computers are connected (when turned on). I called ClearWire support and they said I'd have to check my router's manufacturer to explain the local network activity and could not confirm that the ClearWire modem was kind of "chatty" on the local network. In fact, they had no way to tell if any outside activity (leaving the LAN) was happening through my modem.
    While I'm not overly concerned about the activity light now, while checking the AirPort Management Utility just now, I noticed that under my Monitor tab, the Rx Packets errors on my MacBook are approximately 15 times greater than the actual normal packets. For example, if I have 100,000 normal packets, my (errors) are (1,500,000). Should I be concerned about this? Anyone know why this might be happening or how to fix it? Any advice before I call ClearWire support back? I will admit, I never noticed the errors with my regular DSL, but I did check in the AirPort Management Utility every once in a while and I think they would have stood out.
    -Doug

    I would definately agree with you that the number of error packets you're experiencing is way too high. Might it be the Maximum Transmission Unit (MTU) setting is not optimized with your new ISP?
    To do so, you can use a utility, like Cocktail or via OS X's Terminal.
    As you probably already know, MTU will vary with connection type. Cable and non-PPPoE, can use up to 1500, whereas PPPoE connections (WinPoet, RASPPPOE, Enternet, etc.) can only use up to 1492.
    The best value for MTU is that value just before the packets get fragmented. To test, use the Ping utility.
    OS X: ping -D -s 1472 www.dslreports.com
    WinXP: ping -f -l 1472 www.dslreports.com
    Reduce 1472 by 10 until you no longer get the “packet needs to be fragmented” error message. Then increase by 1 until you are 1 less from getting the same error message. Add 28 more to this (since your ping packet size, not including IP/ICMP header is 28 bytes). This will be your MaxMTU. (Note: If you can ping thru at 1472, stop, you’re done! Add 28 and your MaxMTU is 1500.)

  • 2960 switch SNMP packet errors vs Device Manager Errors

    So we use the 2960 switches and monitor the in and out packet errors with snmp. The numbers are not the same in the device manager as the numbers we get from snmp. does anyone know a reason why this would be?

    SSL3.0 is disabled in A5(3.1b) and A5(3.2) A5(3.1b) was released in late November 2014 and A5(3.2) was released in April 2015
    https://software.cisco.com/download/release.html?mdfid=281222179&flowid=151&softwareid=282775307&release=A5(3.1b)&relind=AVAILABLE&rellifecycle=&reltype=latest

  • Ath0 and RX packet errors [solved]

    got wlan up with madwifi drivers but it seems the connection could be better
    i noticed when i do ifconfig there are lots of packet errors
    is this something to be concerned about and what can i do to resolve to this?
    ath0 Link encap:Ethernet HWaddr 00:0D:88:CC:A2:89
    inet addr:192.168.1.220 Bcast:192.168.255.255 Mask:255.255.255.0
    inet6 addr: fe80::20d:88ff:fecc:a289/64 Scope:Link
    UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
    RX packets:1725 errors:2326 dropped:0 overruns:0 frame:2326
    TX packets:1600 errors:0 dropped:0 overruns:0 carrier:0
    collisions:0 txqueuelen:200
    RX bytes:1708288 (1.6 Mb) TX bytes:167345 (163.4 Kb)
    Interrupt:9 Memory:d1240000-d1250000

    had to reinstall the madwifi drivers after kernel upgrade and now the errors are gone. guess the first install was misconfigured

  • Cisco Network Assistant not tracking Bandwidth or Packet Errors

    Hello,
    I'm running CNA 5.8(5).  When I go into the Health section I see bar graphs for everything but Bandwidth Utilization and Packet Error Rate.  Those are showing at 0%.  All other windows are showing percentages and I see them updating ever 1 minute per the polling interval.  Switches are 2960s stacked together.
    Does anyone have any idea why I am not getting readings for those 2 categories?
    Thanks in advance.  Replies rated.                  

    Hello,
    I'm running CNA 5.8(5).  When I go into the Health section I see bar graphs for everything but Bandwidth Utilization and Packet Error Rate.  Those are showing at 0%.  All other windows are showing percentages and I see them updating ever 1 minute per the polling interval.  Switches are 2960s stacked together.
    Does anyone have any idea why I am not getting readings for those 2 categories?
    Thanks in advance.  Replies rated.                  

  • Editing vpn connection causes timeout error+ssh proxy error, related?

    Using plasma5, nothing fancy in my setup.
    When i try to edit openvpn connection initially connection window is all blank but the connection name. After a good while controls appear and im greeted with this message:
    Also when i try to connect to ssh that uses proxy i get this:
    ~ % ssh server
    Pass a valid window to KWallet::Wallet::openWallet().
    The kwalletd service has been registered
    Invalid DBus reply:  QDBusError("org.freedesktop.DBus.Error.NoReply", "Message did not receive a reply (timeout by message bus)")
    QDBusConnection: name 'org.kde.kwalletd5' had owner '' but we thought it was ':1.10408'
    FATAL: Cannot get password for user: bit
    ssh_exchange_identification: Connection closed by remote host
    Proxy is configured as:
    ProxyCommand connect -5 -S localhost:9050 $(tor-resolve %h localhost:9050) %p
    Briefly i can see kwallet dialog asking for credentials but then it is replaced by ksshaskpass dialog asking for proxy password. When i start kwallet application window is basically frozen, can resize it only in small bits as if it was waiting on something for second or so and only processing GUI messages for a moment. After a while window can be resized easily but it is still blank, no controls, menus also get stuck until i terminate application forcibly.
    Any idea what am i missing here?

    Hi
    There are many reasons for the error and they are as follows:
    The user is behind a firewall that is blocking ports UDP 4500/500 and/or ESP.
    The VPN client is using connecting on TCP and the default TCP port 10000 for NAT is blocked.
    The internet connection is not stable and some packets are not reaching the ASA or the replies from the ASA aren’t getting to the client, hence the client thinks the server is no longer available.
    The VPN client is behind a NAT device and the ASA doesn’t have NAT-T enabled. In this case the user will not be able to send or receive traffic at all. It will be able to connect but that’s all. After some time the software client deletes the VPN tunnel.
    Suggested solutions:
    If you are using wireless, try to connect with cable
    Turn your firewall off, then test the connection to see whether the problem still occurs. If it doesn’t then you can turn your firewall back on, add exception rules for port 500, port 4500 and the ESP protocol in your firewall
    Turn on NAT-T/TCP in your profile ( remember to unblock port 10000 in your firewall)
    Edit your profile with your editor and change ForceKeepAlive=0 to 1

  • VPN 3002 Statistics Showing errors

    Overview: Several times a day connectivity is dropped between remote office and home office. 3002 Statistics show the following errors:
    In IP Statistics:
    Outbound Packets with No Route 11816
    Fragmentation Failure 2020
    ICMP Statistics:
    Destination Unreachable rx 1 tx 11825
    SMMP Statistics:
    Bad Community String 1
    ***Private speed from VPN3002 to Switch is 100mb Full.....Public Speed is 10mb half. The Public Side is set to auto detect due to router configuration.
    Any ideas?

    As I see Fragmentation Failure 2020 this seems to be an issue with fragmentation. Try increasing the MTU size. To generally largest MTU size on a path use ping -f -l . http://www.cisco.com/univercd/cc/td/doc/product/vpn/vpn3002/4_0/referenc/interfa.htm#1002870

  • SSL VPN Problem - ACL Parse Error

    Hi there.
    Testing some features in Cisco ASA SSL VPN(Clientless).
    But when i connect to the portal, trying to login i get the following error, anybody seen this before?
    It works if i ADD a ACL to the DAP, but dosn't if there is only a WEBACL applied??
    It also works if i remove my "check" in "ssl-client" box in the global_policy  (Group Policy).
    6|Mar 20 2014|16:45:09|716002|||||Group <global_policy> User <[email protected]> IP <X.X.X.X> WebVPN session terminated: ACL Parse Error.
    7|Mar 20 2014|16:45:09|720041|||||(VPN-Primary) Sending Delete WebVPN Session message user [email protected], IP X.X.X.X to standby unit
    4|Mar 20 2014|16:45:09|716046|||||Group <global_policy> User <[email protected]> IP <X.X.X.X> User ACL <testcustomer_attribute> from AAA dosn't exist on the device, terminating connection.
    7|Mar 20 2014|16:45:09|720041|||||(VPN-Primary) Sending Create ACL List message rule DAP-web-user-E4EAC90F, line 1 to standby unit
    7|Mar 20 2014|16:45:09|720041|||||(VPN-Primary) Sending Create ACL Info message DAP-web-user-E4EAC90F to standby unit
    6|Mar 20 2014|16:45:09|734001|||||DAP: User [email protected], Addr X.X.X.X, Connection Clientless: The following DAP records were selected for this connection: testcustomer_common_dap
    7|Mar 20 2014|16:45:09|734003|||||DAP: User [email protected], Addr X.X.X.X: Session Attribute aaa.cisco.tunnelgroup = common_tunnelgroup
    7|Mar 20 2014|16:45:09|734003|||||DAP: User [email protected], Addr X.X.X.X: Session Attribute aaa.cisco.username2 =
    7|Mar 20 2014|16:45:09|734003|||||DAP: User [email protected], Addr X.X.X.X: Session Attribute aaa.cisco.username1 = [email protected]
    7|Mar 20 2014|16:45:09|734003|||||DAP: User [email protected], Addr X.X.X.X: Session Attribute aaa.cisco.username = [email protected]
    7|Mar 20 2014|16:45:09|734003|||||DAP: User [email protected], Addr X.X.X.X: Session Attribute aaa.cisco.grouppolicy = global_policy
    7|Mar 20 2014|16:45:09|734003|||||DAP: User [email protected], Addr X.X.X.X: Session Attribute aaa.radius["11"]["1"] = testcustomer_attribute
    6|Mar 20 2014|16:45:09|113008|||||AAA transaction status ACCEPT : user = [email protected]
    6|Mar 20 2014|16:45:09|113009|||||AAA retrieved default group policy (global_policy) for user = [email protected]
    6|Mar 20 2014|16:45:09|113004|||||AAA user authentication Successful : server =  X.X.X.X : user = [email protected]

    If you have implemented SSLVPN i18n then I think you are hitting bug.

Maybe you are looking for