Re: [fw-wiz] Cisco ASA IKE Initiator unable to find policy



I had a similar issue. I fixed it by recreating a new policy from
scratch and assigning a different encryption/Hash to the policy that was
unique from everything else. Also, make sure to label your crypto policy
to be the lowest number.

-----Original Message-----
From: firewall-wizards-bounces@xxxxxxxxxxxxxxxxxxxxx
[mailto:firewall-wizards-bounces@xxxxxxxxxxxxxxxxxxxxx] On Behalf Of
Jens Brey
Sent: Wednesday, November 12, 2008 12:05 PM
To: Firewall Wizards Security Mailing List
Subject: [fw-wiz] Cisco ASA IKE Initiator unable to find policy

Dear all,

i have the following problem. I have a ASA 5520 running 8.0.4. After
some time, i see the following problem. Some of the Site-to-Site VPN
tunnels terminated on the device doesn't pass any traffic anymore, but
the VPN tunnel itself is still up.

It looks like the cryptomap looses the assignment to the ACL policy and
so, i see the following messages in the Cisco log:

"IKE Initiator unable to find policy"

I saw this behaviour also under 8.0.3.

Somebody a idea?

Regards,
Jens
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards


_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • Re: assigning software in Win 2003
    ... Now recently under this policy itself added software 7zip.msi to be assigned to all user. ... Assigning the software to all users in the domain is something I wouldn't do - as it gets installed on all machines users log on. ... Server, DCs, ... ... Try to use the Computer Configuration part instead and assign that app to the machines. ...
    (microsoft.public.windows.group_policy)
  • Re: Group Policy to Apply to All Users on certain Servers
    ... > Assigning a more restrictive policy to ALL users of a TS is easy. ... > logon to their PCs and another policy to users when they logon to a server ...
    (microsoft.public.windows.server.active_directory)
  • RE: Group Policy to Apply to All Users on certain Servers
    ... Assigning a more restrictive policy to ALL users of a TS is easy. ... logon to their PCs and another policy to users when they logon to a server is ... > What we want to do is apply certain restrictions to PC / Notebook users, but when those same users log into a Terminal Server they have a more restrictive GPO applied. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Solution: Suddenly macro doesnt work---why did this work?????
    ... That can be in a Contacts folder too, ... It's best policy to either check for an error and handle it after the assignment or by assigning the item to an Object first, then testing item.Class for olContact before assigning it to a ContactItem object. ...
    (microsoft.public.outlook.program_vba)