Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Westi on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Encrypt packets and decrypt packets does not match

Status
Not open for further replies.

dipul8213

MIS
Sep 23, 2003
2
US
I have vpn setup on my pix firewall running 6.3. When I ping the inside network from my pc at home I see for every 10 packets encrypted only packets are decrypted . Is this normal? Why I am seeing this behaviour? or am i missing something


 
Are you using split tunneling or allowing local lan access? It could be that you are encypting everything out of the client but not all the traffic you are sending should be sent through the VPN tunnel.

i.e if you don't have split tunneling on you could be encrypting spurious traffic that the network at the end of the VPN can't deal with and just drops, you would see traffic being encrypted down the tunnel but no replies would come.

I saw a problem like this caused be ARP broadcasts.

A good way to find out is to install ethereal or another packet sniffer on the system with the client and run it on the VPN interface (if you have the new client that installs a VPN interface that is) you can see all of the packets that are encrypted and see what should/shouldn't be there.

HTH

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top