?
Solved

ASA 5520 ASDM Syslog messages

Posted on 2013-12-17
7
Medium Priority
?
622 Views
Last Modified: 2013-12-24
Hello,

I'm seeing the asdm syslog messages roll by with the following:

IP = <IP Address> Header invalid, missing SA payload! (next payload = 4)

I do have VPNs configured, one site-to-site and the other a regular one. Neither of those originate from the IP address mentioned.

I put that IP into a drop ACL at the begining on the outside interface and it still keeps on coming.

Any idea on what this is and why its happening? How do i stop it?

Thanks
0
Comment
Question by:netcmh
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
7 Comments
 
LVL 8

Expert Comment

by:TMekeel
ID: 39724479
Did you remove any VPNs?

Can you try clear crypto isakmp sa invalid ip address?

edited for I typed the command incorrectly....
0
 
LVL 21

Author Comment

by:netcmh
ID: 39724634
When I issued that command, I got this:

Can't find a valid tunnel group, aborting...

I don't have that IP anywhere in my config.
0
 
LVL 8

Expert Comment

by:TMekeel
ID: 39725053
Can you try rebooting the device and see if it persists?
0
Flexible connectivity for any environment

The KE6900 series can extend and deploy computers with high definition displays across multiple stations in a variety of applications that suit any environment. Expand computer use to stations across multiple rooms with dynamic access.

 
LVL 21

Author Comment

by:netcmh
ID: 39725072
I could. It'll have to wait till maintenance window. Early next month.

Anything else I could try in the mean while?
0
 
LVL 8

Expert Comment

by:TMekeel
ID: 39725576
The only thing I could think of is to reset the tunnel, but we tried clearing already, and you have an ACL to block inbound on the outside interface...not sure what else to do besides reboot or call TAC and ask!


Perhaps another Expert can chime in;  I'm sorry I don't know off the top of my head.  I will try some google-fu for you though and see if I can gain some knowledge to pass on.
0
 
LVL 21

Accepted Solution

by:
netcmh earned 0 total points
ID: 39729800
Got it figured out.

Did a reverse IP lookup. Found the company. Called them.

They had a vendor with that IP earlier. Got in touch with their infrastructure team, verified that the config belonged to the old vendor (who has now changed their IP), and had it removed.

The sessions stopped.
0
 
LVL 21

Author Closing Comment

by:netcmh
ID: 39737638
This was the solution.
0

Featured Post

Video: Liquid Web Managed WordPress Comparisons

If you run run a WordPress, you understand the potential headaches you may face when updating your plugins and themes. Do you choose to update on the fly and risk taking down your site; or do you set up a staging, keep it in sync with your live site and use that to test updates?

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A 2007 NCSA Cyber Security survey revealed that a mere 4% of the population has a full understanding of firewalls. As business owner, you should be part of that 4% that has a full understanding.
This month, Experts Exchange’s free Course of the Month is focused on CompTIA IT Fundamentals.
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…
Suggested Courses

765 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question