Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

ASA 5520 ASDM Syslog messages

Posted on 2013-12-17
7
604 Views
Last Modified: 2013-12-24
Hello,

I'm seeing the asdm syslog messages roll by with the following:

IP = <IP Address> Header invalid, missing SA payload! (next payload = 4)

I do have VPNs configured, one site-to-site and the other a regular one. Neither of those originate from the IP address mentioned.

I put that IP into a drop ACL at the begining on the outside interface and it still keeps on coming.

Any idea on what this is and why its happening? How do i stop it?

Thanks
0
Comment
Question by:netcmh
  • 4
  • 3
7 Comments
 
LVL 8

Expert Comment

by:TMekeel
ID: 39724479
Did you remove any VPNs?

Can you try clear crypto isakmp sa invalid ip address?

edited for I typed the command incorrectly....
0
 
LVL 20

Author Comment

by:netcmh
ID: 39724634
When I issued that command, I got this:

Can't find a valid tunnel group, aborting...

I don't have that IP anywhere in my config.
0
 
LVL 8

Expert Comment

by:TMekeel
ID: 39725053
Can you try rebooting the device and see if it persists?
0
Portable, direct connect server access

The ATEN CV211 connects a laptop directly to any server allowing you instant access to perform data maintenance and local operations, for quick troubleshooting, updating, service and repair.

 
LVL 20

Author Comment

by:netcmh
ID: 39725072
I could. It'll have to wait till maintenance window. Early next month.

Anything else I could try in the mean while?
0
 
LVL 8

Expert Comment

by:TMekeel
ID: 39725576
The only thing I could think of is to reset the tunnel, but we tried clearing already, and you have an ACL to block inbound on the outside interface...not sure what else to do besides reboot or call TAC and ask!


Perhaps another Expert can chime in;  I'm sorry I don't know off the top of my head.  I will try some google-fu for you though and see if I can gain some knowledge to pass on.
0
 
LVL 20

Accepted Solution

by:
netcmh earned 0 total points
ID: 39729800
Got it figured out.

Did a reverse IP lookup. Found the company. Called them.

They had a vendor with that IP earlier. Got in touch with their infrastructure team, verified that the config belonged to the old vendor (who has now changed their IP), and had it removed.

The sessions stopped.
0
 
LVL 20

Author Closing Comment

by:netcmh
ID: 39737638
This was the solution.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Claiming a Domain Name 7 52
Support licences 3 26
Failover VPN Question Sonicwall 5 48
what is mstp 6 34
Meet the world's only “Transparent Cloud™” from Superb Internet Corporation. Now, you can experience firsthand a cloud platform that consistently outperforms Amazon Web Services (AWS), IBM’s Softlayer, and Microsoft’s Azure when it comes to CPU and …
I had an issue with InstallShield not being able to use Computer Browser service on Windows Server 2012. Here is the solution I found.
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

856 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question