User guide
31
Release Notes for Cisco Router and Security Device Manager 2.5
OL-5009-20
Caveats
• CSCsa40535
VPN status in the Monitor windows do not show IPsec security association (SA) parameters for
DMVPN when CLI status commands report that the crypto tunnels are up and traffic is passing
through. The DMVPN tunnel is shown as established in the IKE SA tab.
Workaround: Use the CLI to view DMVPN status.
• CSCef34056
If multiple instances of Cisco SDM are run under Netscape version 7.1 using the Java Virtual
Machine (JVM) or the Java plug-in, and the user shuts down one instance of Cisco SDM, then all
other open instances of Cisco SDM on that PC are shut down.
This problem occurs because Netscape version 7.1 uses only one instance of the JVM or the Java
plug-in, even when multiple instances of Netscape are launched. As a result, when one instance of
Cisco SDM is shut down, Netscape shuts down the JVM or the Java plug-in, and all other instances
of Cisco SDM are also shut down.
Workaround: If Cisco SDM is run under Netscape version 7.1, open only one instance of
Cisco SDM. Using Internet Explorer is advised when multiple instances of Cisco SDM must be
opened, such as when the user must configure multiple routers at the same time.
• CSCef43267
When the crypto identity ca command is used, the Loopback0 interface is shown as having no
configured IP address in the Edit Interfaces and Connections window when an IP address has been
configured.
Workaround: Disregard the IP address information in the Interfaces and Connections window. If
you need to view the IP address, choose the interface and click the Edit button.
• CSCef50389
When an Easy VPN Server is configured using Digital Certificates for authentication, and an Easy
VPN Remote connection is configured on another router, the client statistics for the Easy VPN
server are all shown as 0 in the VPN Status window.
Workaround: To view client statistics, choose Too l s > Telnet. Log in to the router, and issue the
show crypto session command.
• CSCef57546
When adding a new signature to the ATOMIC.ICMP engine, you may see the error message
“[Enum(xxx)-StorageKey-ATOMIC.ICMP] the value AaBb is not a valid value.”
Workaround: In the Add Signature window, go to the parameter StorageKey, and click the green
square to enable editing for this parameter. the green square icon will change to a red diamond icon.
Choosing any value from the drop down box will fix this problem.
• CSCef63313
If an Easy VPN Remote configuration has connections to more than one Easy VPN server
configured, VPN troubleshooting deactivating may report troubleshooting results for only one VPN
server or give incorrect recommendations. This issue is seen only in some Cisco IOS images.
Workaround: None.
• CSCef72022
Invoking Cisco SDM with a user associated with SDM_Monitor view adds a PKI trust point and an
Easy VPN profile. This behavior does not affect the running configuration.
Workaround: Invoke Cisco SDM with a user associated with a different CLI view, or with a user
of privilege level 15.