<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DMVPN GRE over IPSEC Packet loss in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dmvpn-gre-over-ipsec-packet-loss/m-p/633551#M1054793</link>
    <description>&lt;P&gt;I have a hub and spoke DMVPN GRE over IPSec topology.  We have many sites, over 10, and have a problem on one particular site, just one.  First off I want to say that I have replaced the Router and I get the same exact errors.  By monitoring the Terminal, I regularly get these messages&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%VPN_HW-1-PACKET_ERROR: slot: 0 Packet Encryption/Decryption error, Output Authentication error:srcadr=10.X.X.X,dstadr=10.X.X.X,size=616,handle=0x581A&lt;/P&gt;&lt;P&gt;%CRYPTO-4-RECVD_PKT_MAC_ERR: decrypt: mac verify failed for connection id=1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The tunnel is up, passes data, and always stays up.  This router is a Spoke router.  The routing protocol being used is EIGRP.  When I do a &lt;/P&gt;&lt;P&gt;Show Crypto isakmp sa, it shows the state as being "QM_IDLE" which means it is up.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I use the "Show Crypto Engine accelerator stat" this is what I get (Attached File)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can see that there are ppq rx errors, authentication errors, invalid packets, and packets dropped.  I know this is not due to mis-configuration because the config is the same exact as other sites that I have which never have any problems.  Here is the tunnel interface and the tunnel source interface on the Spoke Router&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; interface Tunnel111&lt;/P&gt;&lt;P&gt; description **DPN VPN**&lt;/P&gt;&lt;P&gt; bandwidth 1000&lt;/P&gt;&lt;P&gt; ip address 172.31.111.107 255.255.255.0&lt;/P&gt;&lt;P&gt; no ip redirects&lt;/P&gt;&lt;P&gt; no ip unreachables&lt;/P&gt;&lt;P&gt; no ip proxy-arp&lt;/P&gt;&lt;P&gt; ip mtu 1300&lt;/P&gt;&lt;P&gt; ip pim sparse-dense-mode&lt;/P&gt;&lt;P&gt; ip nhrp authentication XXXX&lt;/P&gt;&lt;P&gt; ip nhrp map multicast dynamic&lt;/P&gt;&lt;P&gt; ip nhrp map multicast X.X.X.X&lt;/P&gt;&lt;P&gt; ip nhrp map X.X.X.X X.X.X.X&lt;/P&gt;&lt;P&gt; ip nhrp network-id 100002&lt;/P&gt;&lt;P&gt; ip nhrp holdtime 360&lt;/P&gt;&lt;P&gt; ip nhrp nhs 172.31.111.254&lt;/P&gt;&lt;P&gt; ip route-cache flow&lt;/P&gt;&lt;P&gt; ip tcp adjust-mss 1260&lt;/P&gt;&lt;P&gt; ip summary-address eigrp 100 10.X.X.X 255.255.0.0 5&lt;/P&gt;&lt;P&gt; qos pre-classify&lt;/P&gt;&lt;P&gt; tunnel source GigabitEthernet0/0&lt;/P&gt;&lt;P&gt; tunnel mode gre multipoint&lt;/P&gt;&lt;P&gt; tunnel key XXXX&lt;/P&gt;&lt;P&gt; tunnel protection ipsec profile X.X.X.X&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt; description **TO DPNVPN**&lt;/P&gt;&lt;P&gt; ip address 10.X.X.X 255.255.255.0&lt;/P&gt;&lt;P&gt; no ip redirects&lt;/P&gt;&lt;P&gt; no ip unreachables&lt;/P&gt;&lt;P&gt; no ip proxy-arp&lt;/P&gt;&lt;P&gt; ip nbar protocol-discovery&lt;/P&gt;&lt;P&gt; ip pim sparse-dense-mode&lt;/P&gt;&lt;P&gt; ip virtual-reassembly&lt;/P&gt;&lt;P&gt; duplex full&lt;/P&gt;&lt;P&gt; speed 100&lt;/P&gt;&lt;P&gt; no snmp trap link-status&lt;/P&gt;&lt;P&gt; no mop enabled&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there anything that you can think of that may becausing this, do you think this can be a layer one or two issue?  Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Brenden&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 09:09:56 GMT</pubDate>
    <dc:creator>nocadmin1</dc:creator>
    <dc:date>2020-02-21T09:09:56Z</dc:date>
    <item>
      <title>DMVPN GRE over IPSEC Packet loss</title>
      <link>https://community.cisco.com/t5/network-security/dmvpn-gre-over-ipsec-packet-loss/m-p/633551#M1054793</link>
      <description>&lt;P&gt;I have a hub and spoke DMVPN GRE over IPSec topology.  We have many sites, over 10, and have a problem on one particular site, just one.  First off I want to say that I have replaced the Router and I get the same exact errors.  By monitoring the Terminal, I regularly get these messages&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%VPN_HW-1-PACKET_ERROR: slot: 0 Packet Encryption/Decryption error, Output Authentication error:srcadr=10.X.X.X,dstadr=10.X.X.X,size=616,handle=0x581A&lt;/P&gt;&lt;P&gt;%CRYPTO-4-RECVD_PKT_MAC_ERR: decrypt: mac verify failed for connection id=1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The tunnel is up, passes data, and always stays up.  This router is a Spoke router.  The routing protocol being used is EIGRP.  When I do a &lt;/P&gt;&lt;P&gt;Show Crypto isakmp sa, it shows the state as being "QM_IDLE" which means it is up.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I use the "Show Crypto Engine accelerator stat" this is what I get (Attached File)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can see that there are ppq rx errors, authentication errors, invalid packets, and packets dropped.  I know this is not due to mis-configuration because the config is the same exact as other sites that I have which never have any problems.  Here is the tunnel interface and the tunnel source interface on the Spoke Router&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; interface Tunnel111&lt;/P&gt;&lt;P&gt; description **DPN VPN**&lt;/P&gt;&lt;P&gt; bandwidth 1000&lt;/P&gt;&lt;P&gt; ip address 172.31.111.107 255.255.255.0&lt;/P&gt;&lt;P&gt; no ip redirects&lt;/P&gt;&lt;P&gt; no ip unreachables&lt;/P&gt;&lt;P&gt; no ip proxy-arp&lt;/P&gt;&lt;P&gt; ip mtu 1300&lt;/P&gt;&lt;P&gt; ip pim sparse-dense-mode&lt;/P&gt;&lt;P&gt; ip nhrp authentication XXXX&lt;/P&gt;&lt;P&gt; ip nhrp map multicast dynamic&lt;/P&gt;&lt;P&gt; ip nhrp map multicast X.X.X.X&lt;/P&gt;&lt;P&gt; ip nhrp map X.X.X.X X.X.X.X&lt;/P&gt;&lt;P&gt; ip nhrp network-id 100002&lt;/P&gt;&lt;P&gt; ip nhrp holdtime 360&lt;/P&gt;&lt;P&gt; ip nhrp nhs 172.31.111.254&lt;/P&gt;&lt;P&gt; ip route-cache flow&lt;/P&gt;&lt;P&gt; ip tcp adjust-mss 1260&lt;/P&gt;&lt;P&gt; ip summary-address eigrp 100 10.X.X.X 255.255.0.0 5&lt;/P&gt;&lt;P&gt; qos pre-classify&lt;/P&gt;&lt;P&gt; tunnel source GigabitEthernet0/0&lt;/P&gt;&lt;P&gt; tunnel mode gre multipoint&lt;/P&gt;&lt;P&gt; tunnel key XXXX&lt;/P&gt;&lt;P&gt; tunnel protection ipsec profile X.X.X.X&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt; description **TO DPNVPN**&lt;/P&gt;&lt;P&gt; ip address 10.X.X.X 255.255.255.0&lt;/P&gt;&lt;P&gt; no ip redirects&lt;/P&gt;&lt;P&gt; no ip unreachables&lt;/P&gt;&lt;P&gt; no ip proxy-arp&lt;/P&gt;&lt;P&gt; ip nbar protocol-discovery&lt;/P&gt;&lt;P&gt; ip pim sparse-dense-mode&lt;/P&gt;&lt;P&gt; ip virtual-reassembly&lt;/P&gt;&lt;P&gt; duplex full&lt;/P&gt;&lt;P&gt; speed 100&lt;/P&gt;&lt;P&gt; no snmp trap link-status&lt;/P&gt;&lt;P&gt; no mop enabled&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there anything that you can think of that may becausing this, do you think this can be a layer one or two issue?  Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Brenden&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 09:09:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmvpn-gre-over-ipsec-packet-loss/m-p/633551#M1054793</guid>
      <dc:creator>nocadmin1</dc:creator>
      <dc:date>2020-02-21T09:09:56Z</dc:date>
    </item>
    <item>
      <title>Re: DMVPN GRE over IPSEC Packet loss</title>
      <link>https://community.cisco.com/t5/network-security/dmvpn-gre-over-ipsec-packet-loss/m-p/633552#M1054797</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you try to turn off the hardware encryption (no crypto engine accelerator) just to see if it's better.  But be careful, cause your CPU% will run much higher, but you only have 10 spokes sites, so it wont be at 100%.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's better to start troubleshooting by layer 1 then layer 2 when it's possible.  Have you ask the site's ISP for packet lost on their side ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Sep 2006 11:31:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmvpn-gre-over-ipsec-packet-loss/m-p/633552#M1054797</guid>
      <dc:creator>martindesrosiers</dc:creator>
      <dc:date>2006-09-13T11:31:07Z</dc:date>
    </item>
  </channel>
</rss>

