<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Getting error messages with IPSec tunnels on FTDv in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/getting-error-messages-with-ipsec-tunnels-on-ftdv/m-p/4746012#M1096300</link>
    <description>&lt;P&gt;My initial though here is that this is a timeout / lifetime issue.&amp;nbsp; Have you verified the timeout values at both ends of the s2s VPN?&lt;/P&gt;</description>
    <pubDate>Wed, 28 Dec 2022 10:39:00 GMT</pubDate>
    <dc:creator>Marius Gunnerud</dc:creator>
    <dc:date>2022-12-28T10:39:00Z</dc:date>
    <item>
      <title>Getting error messages with IPSec tunnels on FTDv</title>
      <link>https://community.cisco.com/t5/network-security/getting-error-messages-with-ipsec-tunnels-on-ftdv/m-p/4741825#M1096072</link>
      <description>&lt;P&gt;We have a firepower running in vmware and are using firepower device manager to manage the device.&lt;BR /&gt;but sporadically we get the message IPSEC:Received an ESP packet from [SiteB] to [SiteA] that failed authentication&lt;BR /&gt;But I can't find out what is causing this error anybody has an idea, when I get the message the tunnel is also down for like 45 minutes.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;IKE policy is set as following:&lt;BR /&gt;Encryption AES192&lt;BR /&gt;DFH: 14&lt;BR /&gt;Integrity hash: SHA256&lt;BR /&gt;PRF hash: SHA256&lt;BR /&gt;Lifetime: 86400&lt;/P&gt;&lt;P&gt;IPSEC proposal&lt;BR /&gt;Encryption AESGCM192&lt;BR /&gt;Integrity hash: SHA256&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2022 14:56:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/getting-error-messages-with-ipsec-tunnels-on-ftdv/m-p/4741825#M1096072</guid>
      <dc:creator>Nathan_study</dc:creator>
      <dc:date>2022-12-19T14:56:53Z</dc:date>
    </item>
    <item>
      <title>Re: Getting error messages with IPSec tunnels on FTDv</title>
      <link>https://community.cisco.com/t5/network-security/getting-error-messages-with-ipsec-tunnels-on-ftdv/m-p/4745786#M1096298</link>
      <description>&lt;P&gt;sorry for late reply but are this issue solved ?&lt;BR /&gt;are you run IKEv2?&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2022 00:39:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/getting-error-messages-with-ipsec-tunnels-on-ftdv/m-p/4745786#M1096298</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-12-28T00:39:58Z</dc:date>
    </item>
    <item>
      <title>Re: Getting error messages with IPSec tunnels on FTDv</title>
      <link>https://community.cisco.com/t5/network-security/getting-error-messages-with-ipsec-tunnels-on-ftdv/m-p/4746012#M1096300</link>
      <description>&lt;P&gt;My initial though here is that this is a timeout / lifetime issue.&amp;nbsp; Have you verified the timeout values at both ends of the s2s VPN?&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2022 10:39:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/getting-error-messages-with-ipsec-tunnels-on-ftdv/m-p/4746012#M1096300</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2022-12-28T10:39:00Z</dc:date>
    </item>
    <item>
      <title>Re: Getting error messages with IPSec tunnels on FTDv</title>
      <link>https://community.cisco.com/t5/network-security/getting-error-messages-with-ipsec-tunnels-on-ftdv/m-p/4746499#M1096338</link>
      <description>&lt;P&gt;Yes I'm running IKEv2&lt;BR /&gt;I have now replaced the IPSEC proposal encryption from AESGCM192 to AES192 and I'm monitoring to see if they are going down&lt;/P&gt;</description>
      <pubDate>Thu, 29 Dec 2022 09:08:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/getting-error-messages-with-ipsec-tunnels-on-ftdv/m-p/4746499#M1096338</guid>
      <dc:creator>Nathan_study</dc:creator>
      <dc:date>2022-12-29T09:08:09Z</dc:date>
    </item>
    <item>
      <title>Re: Getting error messages with IPSec tunnels on FTDv</title>
      <link>https://community.cisco.com/t5/network-security/getting-error-messages-with-ipsec-tunnels-on-ftdv/m-p/4746500#M1096339</link>
      <description>&lt;P&gt;Yes timout is set to 8 hours&lt;/P&gt;</description>
      <pubDate>Thu, 29 Dec 2022 09:08:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/getting-error-messages-with-ipsec-tunnels-on-ftdv/m-p/4746500#M1096339</guid>
      <dc:creator>Nathan_study</dc:creator>
      <dc:date>2022-12-29T09:08:38Z</dc:date>
    </item>
    <item>
      <title>Re: Getting error messages with IPSec tunnels on FTDv</title>
      <link>https://community.cisco.com/t5/network-security/getting-error-messages-with-ipsec-tunnels-on-ftdv/m-p/4748338#M1096417</link>
      <description>&lt;P&gt;is this a site to site VPN, DMVPN, FlexVPN, etc.?&lt;/P&gt;
&lt;P&gt;is one of the sites using dynamic IP or are both static?&lt;/P&gt;
&lt;P&gt;If the issue happens again, check the output of show crypto ipsec sa and verify if the SPI values are the same for the interesting traffic.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2023 11:04:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/getting-error-messages-with-ipsec-tunnels-on-ftdv/m-p/4748338#M1096417</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2023-01-03T11:04:37Z</dc:date>
    </item>
  </channel>
</rss>

