netcmh
asked on
ASA 5520 ASDM Syslog messages
Hello,
I'm seeing the asdm syslog messages roll by with the following:
IP = <IP Address> Header invalid, missing SA payload! (next payload = 4)
I do have VPNs configured, one site-to-site and the other a regular one. Neither of those originate from the IP address mentioned.
I put that IP into a drop ACL at the begining on the outside interface and it still keeps on coming.
Any idea on what this is and why its happening? How do i stop it?
Thanks
I'm seeing the asdm syslog messages roll by with the following:
IP = <IP Address> Header invalid, missing SA payload! (next payload = 4)
I do have VPNs configured, one site-to-site and the other a regular one. Neither of those originate from the IP address mentioned.
I put that IP into a drop ACL at the begining on the outside interface and it still keeps on coming.
Any idea on what this is and why its happening? How do i stop it?
Thanks
ASKER
When I issued that command, I got this:
Can't find a valid tunnel group, aborting...
I don't have that IP anywhere in my config.
Can't find a valid tunnel group, aborting...
I don't have that IP anywhere in my config.
Can you try rebooting the device and see if it persists?
ASKER
I could. It'll have to wait till maintenance window. Early next month.
Anything else I could try in the mean while?
Anything else I could try in the mean while?
The only thing I could think of is to reset the tunnel, but we tried clearing already, and you have an ACL to block inbound on the outside interface...not sure what else to do besides reboot or call TAC and ask!
Perhaps another Expert can chime in; I'm sorry I don't know off the top of my head. I will try some google-fu for you though and see if I can gain some knowledge to pass on.
Perhaps another Expert can chime in; I'm sorry I don't know off the top of my head. I will try some google-fu for you though and see if I can gain some knowledge to pass on.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
This was the solution.
Can you try clear crypto isakmp sa invalid ip address?
edited for I typed the command incorrectly....