locked
What causes the OCS Protocol Stack warnings in the eventlog and how to get rid of it? RRS feed

  • Question

  • In my eventlog I can see the following warning once in a while:

     

    At least one attempt to reference stale (non-existent or deleted) security association was detected.

    There were 1 messages with signature that referenced stale (non-existent or deleted) security association in the last 0 minutes. The last one was this SIP message:

    Instance-Id: 00004EFA
    Direction: no-direction-info

    (..)

     

    Cause: This could be due to users that utilize large number of devices (in excess of configured maximum), or due to connection refresh logic re-balancing remote users to a different director in a bank or a pool, or it could be due to an attacker.
    Resolution:
    None needed unless the failure count is high (>100). Check if number of allowed devices per user is too low for existing usage scenarios. Check your network for any rogue clients. Restart the server if problem persists.

     

    I'm not sure how to implement the suggested resolutions. Or can I just ignore this message?

     

    /Thomas

    Friday, October 19, 2007 3:17 PM

All replies

  • I have the problem too,who have any solutions to fix it,thanks!

    Tuesday, December 18, 2007 9:08 AM
  • I am also getting these sporadic errors.  Is there a fix to suppress these random warnings?  Everything is operating fine...

     

    Keenan

     

    Monday, June 2, 2008 9:27 PM