<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ESP Sequence Number Error in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/esp-sequence-number-error/m-p/1281028#M949037</link>
    <description>&lt;P&gt;I have a site to site IPSec VPN setup to a Cisco 1711 router, and am getting occasional error messages of this type:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%C1700_EM-1-ERROR: packet-rx error: ESP sequence fail, id 60, pool offset 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This appears to be caused by the router seeing a sequence number in the ESP header it doesn't like, which I think happens occasionally because we have low phase 1 and 2 timers (300 seconds).  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to turn off the anti-replay service to see if this would cause the messages to stop, but the IOS version I have doesn't appear to allow that.  The version is Version 12.3(11)T11.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas on how I could get these messages to cease?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 11:40:38 GMT</pubDate>
    <dc:creator>inoc_noc</dc:creator>
    <dc:date>2020-02-21T11:40:38Z</dc:date>
    <item>
      <title>ESP Sequence Number Error</title>
      <link>https://community.cisco.com/t5/network-security/esp-sequence-number-error/m-p/1281028#M949037</link>
      <description>&lt;P&gt;I have a site to site IPSec VPN setup to a Cisco 1711 router, and am getting occasional error messages of this type:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%C1700_EM-1-ERROR: packet-rx error: ESP sequence fail, id 60, pool offset 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This appears to be caused by the router seeing a sequence number in the ESP header it doesn't like, which I think happens occasionally because we have low phase 1 and 2 timers (300 seconds).  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to turn off the anti-replay service to see if this would cause the messages to stop, but the IOS version I have doesn't appear to allow that.  The version is Version 12.3(11)T11.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas on how I could get these messages to cease?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:40:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/esp-sequence-number-error/m-p/1281028#M949037</guid>
      <dc:creator>inoc_noc</dc:creator>
      <dc:date>2020-02-21T11:40:38Z</dc:date>
    </item>
    <item>
      <title>Re: ESP Sequence Number Error</title>
      <link>https://community.cisco.com/t5/network-security/esp-sequence-number-error/m-p/1281029#M949042</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The error message usually indicates the following three possible conditions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) The IPSec encrypted packets are forwarded out of order by the encrypting router.  &lt;/P&gt;&lt;P&gt;2. The IPSec packets received by the decrypting router are out of order due to packet&lt;/P&gt;&lt;P&gt;reordering at an intermediate device.&lt;/P&gt;&lt;P&gt;3. The received IPSec packet is fragmented and requires reassembly before authentication&lt;/P&gt;&lt;P&gt;verification and decryption.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This problem can usually be resolved by decreasing the TCP mss on the outgoing interface of the router by the following command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface outgoing-interface&lt;/P&gt;&lt;P&gt;ip tcp adjust-mss 1350&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Before you make this change, Please clear all you tunnel with the following command:&lt;/P&gt;&lt;P&gt;clear crypto sa&lt;/P&gt;&lt;P&gt;clear crypto isakmp &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Sep 2009 14:24:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/esp-sequence-number-error/m-p/1281029#M949042</guid>
      <dc:creator>vkapoor5</dc:creator>
      <dc:date>2009-09-22T14:24:04Z</dc:date>
    </item>
  </channel>
</rss>

