<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5510 anti-replay window for vpn in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5510-anti-replay-window-for-vpn/m-p/1799680#M533735</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bala,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The command should be "show cryoto ipsec sa" on the ASA and the command to set the value is "set security-association replay window-size &lt;SIZE&gt;" , try it and let me know how it goes.&lt;/SIZE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 12 Aug 2011 06:47:02 GMT</pubDate>
    <dc:creator>varrao</dc:creator>
    <dc:date>2011-08-12T06:47:02Z</dc:date>
    <item>
      <title>ASA 5510 anti-replay window for vpn</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-anti-replay-window-for-vpn/m-p/1799679#M533733</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you anyone tell me the command to view current anti-reply window size in ASA 5510?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:10:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-anti-replay-window-for-vpn/m-p/1799679#M533733</guid>
      <dc:creator>Balakumaresan Saravanan</dc:creator>
      <dc:date>2019-03-11T21:10:41Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 anti-replay window for vpn</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-anti-replay-window-for-vpn/m-p/1799680#M533735</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bala,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The command should be "show cryoto ipsec sa" on the ASA and the command to set the value is "set security-association replay window-size &lt;SIZE&gt;" , try it and let me know how it goes.&lt;/SIZE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Aug 2011 06:47:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-anti-replay-window-for-vpn/m-p/1799680#M533735</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-08-12T06:47:02Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 anti-replay window for vpn</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-anti-replay-window-for-vpn/m-p/1799681#M533738</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Varun,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We couldnt able find window size in that command. i have copied output command here. This is very critical we need to change the window size but before that we want to see the current window size also we are running two tunnels on ASA 5510. Is it possible to change window size for single tunnel or we can change it globally?&amp;nbsp; reply asap. kindly do the needful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;inbound esp sas:&lt;/P&gt;&lt;P&gt;&amp;nbsp; spi: 0x916B73A3 (2439738275)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; transform: esp-3des esp-sha-hmac no compression&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; in use settings ={L2L, Tunnel, }&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; slot: 0, conn_id: 163840, crypto-map: VPN&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sa timing: remaining key lifetime (kB/sec): (3518375/2528)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IV size: 8 bytes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; replay detection support: Y&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Anti replay bitmap:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0xFFFFFFFF 0xFFFFFFFF 0xFFFFFFFF 0xFFFFFFFF&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0xFFFFFFFF 0xFFFFFFFF 0xFFFFFFFF 0xFFFFFFFF&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0xFFFFFFFF 0xFFFFFFFF 0xFFFFFFFF 0xFFFFFFFF&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0xFFFFFFFF 0xFFFFFFFF 0xFFFFFFFF 0xFFFFFFFF&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0xFFFFFFFF 0xFFFFFFFF 0xFFFFFFFF 0xFFFFFFFF&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0xFFFFFFFF 0xFFFFFFFF 0xFFFFFFFF 0xFFFFFFFF&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0xFFFFFFFF 0xFFFFFFFF 0xFFFFFFFF 0xFFFFFFFF&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0xFFFFFFFF 0xFFFFFFFF 0xFFFFFFFF 0xFFFFFFFF&lt;/P&gt;&lt;P&gt;outbound esp sas:&lt;/P&gt;&lt;P&gt;&amp;nbsp; spi: 0x635F2042 (1667178562)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; transform: esp-3des esp-sha-hmac no compression&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; in use settings ={L2L, Tunnel, }&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; slot: 0, conn_id: 163840, crypto-map: VPN&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sa timing: remaining key lifetime (kB/sec): (3549940/2528)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IV size: 8 bytes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; replay detection support: Y&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Anti replay bitmap:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0x00000000 0x00000000 0x00000000 0x00000001&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0x00000000 0x00000000 0x00000000 0x00000000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0x00000000 0x00000000 0x00000000 0x00000000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0x00000000 0x00000000 0x00000000 0x00000000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0x00000000 0x00000000 0x00000000 0x00000000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0x00000000 0x00000000 0x00000000 0x00000000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0x00000000 0x00000000 0x00000000 0x00000000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0x00000000 0x00000000 0x00000000 0x00000000&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Aug 2011 07:07:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-anti-replay-window-for-vpn/m-p/1799681#M533738</guid>
      <dc:creator>Balakumaresan Saravanan</dc:creator>
      <dc:date>2011-08-12T07:07:50Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 anti-replay window for vpn</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-anti-replay-window-for-vpn/m-p/1799682#M533740</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You should be able to see it in "show run crypto" command, something like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE style="font-family: monospace; font-size: 12px; white-space: -o-pre-wrap; word-wrap: break-word;"&gt;crypto map YNRCPHV02 10 ipsec-isakmp 
 set peer 172.18.100.101
 &lt;STRONG&gt;set security-association replay window-size 256 &lt;/STRONG&gt; set transform-set myset 
 match address asa5510&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;Varun&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Aug 2011 07:44:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-anti-replay-window-for-vpn/m-p/1799682#M533740</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-08-12T07:44:35Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 anti-replay window for vpn</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-anti-replay-window-for-vpn/m-p/1799683#M533741</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This should also help:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show run crypto | in replay&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Aug 2011 07:57:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-anti-replay-window-for-vpn/m-p/1799683#M533741</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-08-12T07:57:33Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 anti-replay window for vpn</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-anti-replay-window-for-vpn/m-p/1799684#M533742</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks varun, Now its coming, thanks for your help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Aug 2011 08:12:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-anti-replay-window-for-vpn/m-p/1799684#M533742</guid>
      <dc:creator>Balakumaresan Saravanan</dc:creator>
      <dc:date>2011-08-12T08:12:31Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 anti-replay window for vpn</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-anti-replay-window-for-vpn/m-p/1799685#M533743</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No issues, glad I could help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Aug 2011 08:15:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-anti-replay-window-for-vpn/m-p/1799685#M533743</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-08-12T08:15:18Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 anti-replay window for vpn</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-anti-replay-window-for-vpn/m-p/1799686#M533744</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi am too getting the messageon my router:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CRYPTO-4-PKT_REPLAY_ERR: decrypt: replay check failed connection id=407, sequence number=455744&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To resolve this I have tried to put the command at remote end node:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto ipsec security-association replay window-size 1024....but no sucess.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me whether both end require the same replay window-size.Present local node has no setting this mean it is default 64 byte. Any1 help will be appreciable.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Feb 2013 01:41:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-anti-replay-window-for-vpn/m-p/1799686#M533744</guid>
      <dc:creator>Sanjay Shaw</dc:creator>
      <dc:date>2013-02-10T01:41:10Z</dc:date>
    </item>
  </channel>
</rss>

