Guest

Preview Tool

Cisco Bug: CSCuo00080 - Syslog showing incorrect vpn-filter applied to users after failover

Last Modified

Nov 08, 2016

Products (1)

  • Cisco ASA 5500-X Series Firewalls

Known Affected Releases

8.4(3)

Description (partial)

Symptom:
After ASA is crashed and failover is triggrered, syslog 106103 starts to be logged more frequently on the new active ASA and the log shows that user`s traffic is blocked by a vpn-filter which is not configured under group-policy the user is using.

Conditions:
It happened with many users and various group-pollicy in which vpn-filter was configured. But even if there was a huge amount of logs showing that users were blocked by incorrect vpn-filter, the users appeared to have the correct filter applied and were not getting access blocked to resources that they needed. So it is considered the syslog is just reporting the incorrect vpn-filter.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.