<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IPsec S2S VPN Encap/Decap in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ipsec-s2s-vpn-encap-decap/m-p/2566270#M199228</link>
    <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;i created a S2S VPN and the ASA2's internet connection isn't that good and some packet losses would be 'normal'.&lt;/P&gt;&lt;P&gt;i'm not sure if that relates to the unequal encap/decaps on my 'sh crypto ipsec sa' output.&lt;/P&gt;&lt;P&gt;is the below reading normal?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA1:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #pkts encaps: 129766, #pkts encrypt: 130193, #pkts digest: 130193&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #pkts decaps: 90306, #pkts decrypt: 90306, #pkts verify: 90306&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #pkts compressed: 0, #pkts decompressed: 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #pkts not compressed: 129766, #pkts comp failed: 0, #pkts decomp failed: 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #pre-frag successes: 427, #pre-frag failures: 0, #fragments created: 854&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #PMTUs sent: 0, #PMTUs rcvd: 0, #decapsulated frgs needing reassembly: 29&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #TFC rcvd: 0, #TFC sent: 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #Valid ICMP Errors rcvd: 0, #Invalid ICMP Errors rcvd: 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #send errors: 0, #recv errors: 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA2:&lt;/P&gt;&lt;P&gt;&amp;nbsp;#pkts encaps: 533, #pkts encrypt: 533, #pkts digest: 533&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #pkts decaps: 600, #pkts decrypt: 600, #pkts verify: 600&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #pkts compressed: 0, #pkts decompressed: 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #pkts not compressed: 533, #pkts comp failed: 0, #pkts decomp failed: 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #pre-frag successes: 0, #pre-frag failures: 0, #fragments created: 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #PMTUs sent: 0, #PMTUs rcvd: 0, #decapsulated frgs needing reassembly: 36&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #send errors: 0, #recv errors: 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 05:18:59 GMT</pubDate>
    <dc:creator>johnlloyd_13</dc:creator>
    <dc:date>2019-03-12T05:18:59Z</dc:date>
    <item>
      <title>IPsec S2S VPN Encap/Decap</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-s2s-vpn-encap-decap/m-p/2566270#M199228</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;i created a S2S VPN and the ASA2's internet connection isn't that good and some packet losses would be 'normal'.&lt;/P&gt;&lt;P&gt;i'm not sure if that relates to the unequal encap/decaps on my 'sh crypto ipsec sa' output.&lt;/P&gt;&lt;P&gt;is the below reading normal?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA1:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #pkts encaps: 129766, #pkts encrypt: 130193, #pkts digest: 130193&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #pkts decaps: 90306, #pkts decrypt: 90306, #pkts verify: 90306&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #pkts compressed: 0, #pkts decompressed: 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #pkts not compressed: 129766, #pkts comp failed: 0, #pkts decomp failed: 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #pre-frag successes: 427, #pre-frag failures: 0, #fragments created: 854&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #PMTUs sent: 0, #PMTUs rcvd: 0, #decapsulated frgs needing reassembly: 29&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #TFC rcvd: 0, #TFC sent: 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #Valid ICMP Errors rcvd: 0, #Invalid ICMP Errors rcvd: 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #send errors: 0, #recv errors: 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA2:&lt;/P&gt;&lt;P&gt;&amp;nbsp;#pkts encaps: 533, #pkts encrypt: 533, #pkts digest: 533&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #pkts decaps: 600, #pkts decrypt: 600, #pkts verify: 600&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #pkts compressed: 0, #pkts decompressed: 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #pkts not compressed: 533, #pkts comp failed: 0, #pkts decomp failed: 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #pre-frag successes: 0, #pre-frag failures: 0, #fragments created: 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #PMTUs sent: 0, #PMTUs rcvd: 0, #decapsulated frgs needing reassembly: 36&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #send errors: 0, #recv errors: 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:18:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-s2s-vpn-encap-decap/m-p/2566270#M199228</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2019-03-12T05:18:59Z</dc:date>
    </item>
    <item>
      <title>Hi, I don't think there is</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-s2s-vpn-encap-decap/m-p/2566271#M199229</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't think there is anything unusual about the packet count being different for decaps/encaps&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would imagine that typically the data transfer is uneven so I don't expect ever to see these counters match. Only time is usually when just configuring a new connection and testing it with ICMP which would result in identical count in encap/decap counters (if the ICMP went through) as we would see echo/echo-reply packets.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you would see zero counter on one of the SA pairs then it would indicate a problem&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't see anything special/strange in the above.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jan 2015 13:21:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-s2s-vpn-encap-decap/m-p/2566271#M199229</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2015-01-08T13:21:02Z</dc:date>
    </item>
    <item>
      <title>thanks jouni!are you going to</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-s2s-vpn-encap-decap/m-p/2566272#M199230</link>
      <description>&lt;P&gt;thanks jouni! maybe i got used to seeing equal encap/decap count during initial config and ping test.&lt;/P&gt;&lt;P&gt;are you going to update your NAT docu soon? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;it seems there's a slight update on newer image releases.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jan 2015 17:08:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-s2s-vpn-encap-decap/m-p/2566272#M199230</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2015-01-08T17:08:24Z</dc:date>
    </item>
  </channel>
</rss>

