Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations John Tel on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

thread35-658905

Status
Not open for further replies.

vince62s

Technical User
Nov 8, 2003
109
FR

same pb as in the thread thread35-658905

keepalive is not solving the pb.
PIX is 6.2 on 515

any idea?
 
I replicated this


except that my PIX is 6.2

it works fine each time I clear crypto sa, but at expiration of ipsec lifetime, it renegociates, looks fine but then loses tunnel.

debuging on PIX gives nothing
debuging on router says:
%CRYPTO .. replay error.
then I removed the esp-md5-hmac in transfor set but new error at rekey:
%CRYPTO ...bad length.


then I tried to avoid IKE and have a manual IPSEC conf:
router gives an error:
%..manual stuffing...no valide engine ...id 0


any idea?
is 12.0(7)T buggy ?
 
Try taking repalcing this:

esp-md5-hmac

with:

esp-sha-hmac

Here is the Bug:


Release Notes

When you configure output interfaces with fast switching on a Cisco 1700
series router, IP Security (IPSec) traffic might report replay errors for
certain packets because IPSec decryption connection identifiers are not
saved correctly when the packets are coalesced from protocol control
information (PCI) memory to DRAM. The replay errors usualy appear in incoming
traffic. A Media Access Control (MAC) verify failure error might also appear.
There is no workaround.



You may want to do this during a change window because you will need to clear the isakmp and ipsec sa's.
 

Thanks, I will try. However my router is a 2621 router. does it make a difference?
Also I did not enable fastswitching, I think.

I will try, it does not hurt.

do I have to change also the hash method too ?

(line : isakmp policy 21 hash md5)

 


12.0(7)T on the router
6.2 on the PIX
 
You are a few revs behind on both the Pix and the Router. Is there a reason? Try upgrading your Router if you can. I think the latest rev out is 12.4. Check out your hardware requirments. I would also upgrade the Pix if possible.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top