FREE TEXT QUERY  
  GUIDED SEARCH  
  VIEW ALL SOLUTIONS  

Knowledge Base:
  
 




Feedback
Please rate this solution.
 Excellent
 Good
 Average
 Fair
 Poor
This solution solved my problem.
 Yes
 No
Suggestions for improvement.
(Please include your email address if you would like to hear from us).
 


Search Result
Case Number K55415940
Title The Easy VPN Remote tunnel fails to open on a PIX/ASA firewall after reboot, and the "* Remove 'aaa authentication listener' configuration" error message appears at boot time
Core issue

This issue is due to the presence of Cisco bug ID CSCsh75977.

In this issue, after a reboot of the PIX or ASA firewall, the Easy VPN Remote tunnel does not open. At boot time, the firewall displays an error on the console similar to this:

.* Remove 'aaa authentication listener' configuration

CONFIG CONFLICT: Configuration that would prevent successful Cisco Easy VPN Remote operation has been detected, and is listed above. Please resolve the above configuration conflict(s) and re-enable.


The
show running-config command shows that two or more aaa authentication listener commands are added automatically, and that the vpnclient enable command is removed.

The defect only occurs if the interface used by VPN Remote is configured with a dynamic IP address, which is either Dynamic Host Control Protocol (DHCP) or Point-to-Point over Ethernet (PPoE).

Resolution

The workaround for this issue is to remove the aaa authentication listener command, then issue the vpnclient enable command in configuration mode.

In order to completely resolve this issue, downgrade the PIX/ASA to version 7.2(1) or upgrade to version 7.2(2.14) and later.

Refer to Cisco Downloads in order to download the suggested PIX/ASA software versions.

Problem Type Troubleshoot software feature
Product Family
Firewall - PIX 500 series
ASA Hardware & Software
Frequency Continuously
Error Remove 'aaa authentication listener' configuration
PIX Software Version PIX version 7.x
ASA Software Version 7.2
PIX Model
535
515E
520
525
ASA Models
ASA 5500
ASA 5510
ASA 5520
ASA 5540
VPN Tunnel End Points
PIX
ASA
Features & Tasks Easy VPN
VPN Protocols IPSec
VPN Tunnel Initialization IPSec session is not established
Bug ID Bug ID not listed
Direct URL http://www.ciscotaccc.com/security/showcase?case=K55415940