When deploying a site-to-site IKEv1 IPSec VPN on a Cisco ASA using version 9.1(5)16 or 9.1(5)32 software, you may receive the following error:

ASA1(config)# crypto ikev1 enable OUTSIDE ERROR: CTM ipsec poll ctl DU_IOCTL_RESUME_POLL ioctl failed.

This seems to be a bug that has to do with version 9.1(5)16 as well as 9.1(7)32. This behavior has been experienced usually after an ASA software upgrade to one of these versions, but according to some, the problem does not disappear the software is downgraded to a previously working version. Others have had to open TAC cases to resolve it.

There doesn’t seem to be any published solution to the issue beyond approaching TAC.