<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"> 
  <channel>
  <title>IOS VPN Hot Issues from Cisco TAC</title>
  <link>http://www.cisco.com/en/US/customer/products/sw/voicesw/ps556/products_tech_note09186a0080937324.shtml</link>
  <description>Hot Issues from Cisco TAC.  Please click the link for complete details.</description>
  <language>en-us</language>

  <managingEditor>wsisk@cisco.com (Wes Sisk)</managingEditor>
  <webMaster>news-at-cisco-rss@cisco.com (Cisco Newsroom)</webMaster>
  <pubDate>Mon, 23 Nov 2009 12:19:48 EST</pubDate>
  <lastBuildDate>Mon, 23 Nov 2009 12:19:48 EST</lastBuildDate>
  <generator>PERL</generator>

  <docs>http://www.cisco.com/en/US/customer/products/sw/voicesw/ps556/products_tech_note09186a0080937324.shtml</docs>
  <ttl>10080</ttl>

<item>
<title>IPSec - router logs spurious RECVD_PKT_MAC_ERR messages , Fixed CSCsv43145</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCsv43145</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;
A Cisco IOS router terminating an IPSec tunnel may log the following mac authentication errors:

*Oct 31 18:25:58.943: %CRYPTO-4-RECVD_PKT_MAC_ERR: decrypt: mac verify failed for connection id=2001 local=10.1.1.2 remote=10.1.1.1 spi=9E092279 seqno=00000001  

This is just cosmetic and should not have any functional impact.
&lt;br&gt;
&lt;B&gt;Conditions:&lt;/B&gt;
Router is an IPSec end point with ESP (Encapsulating Security Payload) authentication enabled.
&lt;br&gt;
&lt;B&gt;Workaround:&lt;/B&gt;
There is no known workaround at this time.

</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCsv43145</guid>
</item>
<item>
<title>%SYS-2-BADSHARE: Traceback @datagram_done , Fixed CSCtb07338</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCtb07338</link>
<description>Symptoms: A traceback may occur.
&lt;br&gt;
Conditions: This symptom is observed after a crypto map is removed and 
reapplied.
&lt;br&gt;
Workaround: Use software encryption.


</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCtb07338</guid>
</item>
<item>
<title>Crash due to CPU Error CPU address out of range , Fixed CSCse96332</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCse96332</link>
<description>






&lt;B&gt;Symptom:&lt;/B&gt;
A Cisco 7200 router with NPE-G2 may unexpectedly crash due to SegV exception crash







&lt;br&gt;
&lt;B&gt;Conditions:&lt;/B&gt;
Conditions are unknown at this time




&lt;br&gt;
&lt;B&gt;Workaround:&lt;/B&gt;



&lt;br&gt;
&lt;B&gt;Further Problem Description:&lt;/B&gt;














</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCse96332</guid>
</item>
<item>
<title>VSA:: %SYS-3-INVMEMINT: Invalid memory action (malloc) in stress-test , Open CSCta65018</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCta65018</link>
<description>
&lt;B&gt;Symptom:&lt;/B&gt;
Tracebacks showing malloc failure in datapath.
&lt;br&gt;
&lt;B&gt;Conditions:&lt;/B&gt;
Only at high CPU stress
&lt;br&gt;
&lt;B&gt;Workaround:&lt;/B
No workaround


</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCta65018</guid>
</item>
<item>
<title>Router crashing at crypto_ikmp_hardware_check_and_send_dpd , Fixed CSCsy10608</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCsy10608</link>
<description>
Symptom:
 
 Router crashing once a day
&lt;br&gt; 
 Conditions:
 
 Unknown
&lt;br&gt; 
 Workaround:
 
downgrade to 12.4(21)



</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCsy10608</guid>
</item>
<item>
<title>DMVPN Ph3: NHRP registration issue and tunnel flapping 1 &amp; 2 level hubs , Fixed CSCsz48914</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCsz48914</link>
<description>Symptoms: Next Hop Resolution Protocol (NHRP) registration and tunnels are not
up between first- and second-level hubs.
&lt;br&gt;
Conditions: Occurs in hierarchical topology.
&lt;br&gt;
Workaround: There is no workaround.

 



</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCsz48914</guid>
</item>
<item>
<title>Bus error crash at rn_match part II , Fixed CSCta69213</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCta69213</link>
<description>






&lt;B&gt;Symptom:&lt;/B&gt;
A Cisco router configured for NHRP may crash due to a bus error.






&lt;br&gt;
&lt;B&gt;Conditions:&lt;/B&gt;
Cisco router running IOS with the fix for CSCsv40340 configured for NHRP and DMVPN.




&lt;br&gt;
&lt;B&gt;Workaround:&lt;/B&gt;
None


&lt;br&gt;
&lt;B&gt;Further Problem Description:&lt;/B&gt;














</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCta69213</guid>
</item>
<item>
<title>%SYS-2-GETBUF at Crypto PAS Proc when pkts dropped by ACL with VSA , Fixed CSCsr48828</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCsr48828</link>
<description>Symptoms: A Cisco router may display the following traceback:
 %SYS-2-GETBUF
&lt;br&gt;  
 Conditions: The symptom occurs when ACLs are configured on the WAN 
interfaces of the router. When outbound packets fail and are dropped on an 
outbound ACL, a traceback is generated. If the packets are stopped or the 
ACLs removed, the tracebacks stop. The problem is seen with the VSA 
accelerator, but not seen when software crypto is used.
&lt;br&gt;  
 Workaround: There is no workaround. 
 
  
 
 



</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCsr48828</guid>
</item>
<item>
<title>Sup Crash on several locations with IP SEC config , Open CSCtc79335</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCtc79335</link>
<description>






&lt;B&gt;Symptom:&lt;/B&gt;
SUP crashed on several sites
&lt;br&gt;
&lt;B&gt;Conditions:&lt;/B&gt;
Suspect the IPSEC VPN config.
&lt;br&gt;
&lt;B&gt;Workaround:&lt;/B&gt;



&lt;br&gt;
&lt;B&gt;Further Problem Description:&lt;/B&gt;














</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCtc79335</guid>
</item>
<item>
<title>Bus error crash at rn_match , Fixed CSCsv40340</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCsv40340</link>
<description>Symptoms: A Cisco router may reload due to a bus error.
&lt;br&gt;
Conditions: This symptom is observed on a Cisco 3845 router that is running 
Cisco IOS Release 12.4(15)T7.  The router is configured with NHRP.
&lt;br&gt;
Workaround: There is no workaround.
 



</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCsv40340</guid>
</item>
<item>
<title>ASR crashes at imgr_aom_obj_descr_show , Fixed CSCtd00644</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCtd00644</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;
ASR ungraceful restart with scaled config.
&lt;br&gt;
&lt;B&gt;Conditions:&lt;/B&gt;
When there is scaled config and sessions are flapping frequently.  Sometimes ASR restarts
ungracefully.  This problem is also timing related, so does not happen with every time sessions
flaps.
&lt;br&gt;
&lt;B&gt;Workaround:&lt;/B&gt;
No known workaround

</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCtd00644</guid>
</item>
<item>
<title>P1 SA stuck in KEY_EXCH forever , Fixed CSCsy07555</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCsy07555</link>
<description>Cisco IOS devices that are configured for Internet Key Exchange (IKE) protocol and certificate based authentication are vulnerable to a resource exhaustion attack. Successful exploitation of this vulnerability may result in the allocation of all available Phase 1 security associations (SA) and prevent the establishment of new IPsec sessions.

Cisco has released free software updates that address this vulnerability.

This advisory is posted at http://www.cisco.com/warp/public/707/cisco-sa-20090923-ipsec.shtml

</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCsy07555</guid>
</item>
<item>
<title>Crash at k_cipsStaticCryptomapEntry_get within SNMP , Fixed CSCeh37349</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCeh37349</link>
<description>Symptoms:
The router crashes while walking the cipsStaticCryptomapTable
&lt;br&gt;
Condition:
Only happens in a crypto image
&lt;br&gt;
Workaround:
1) Do not walk the cipsStaticCryptomapTable.
2) Exclude the cipsStaticCryptomapTable from the default view.


</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCeh37349</guid>
</item>
   
</channel>
</rss>
