<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 2 IPSEC Flows same network?!? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/2-ipsec-flows-same-network/m-p/1235317#M957717</link>
    <description>&lt;P&gt;Ok I can only think that my peer is using some sort of load balancing or something. But basically if you notice the info below for some reason there are 2 IPSEC flow's for each network. The data session dies when 1 of the IPsec flows timer expires until the other IPsec flow timer expires. After renegotiation Im good for about 57 minutes until the process repeats itself. Any suggestions is greatly appreciated. This is on a 7206 btw.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Peer: P.P.P.P/500 fvrf: (none) ivrf: (none)&lt;/P&gt;&lt;P&gt;      Phase1_id: P.P.P.P&lt;/P&gt;&lt;P&gt;      Desc: (none)&lt;/P&gt;&lt;P&gt;  IKE SA: local ME.ME.ME.ME/500 remote P.P.P.P/500 Active &lt;/P&gt;&lt;P&gt;          Capabilities:(none) connid:35 lifetime:19:08:44&lt;/P&gt;&lt;P&gt;  IKE SA: local ME.ME.ME.ME/500 remote P.P.P.P/500 Active &lt;/P&gt;&lt;P&gt;          Capabilities:(none) connid:36 lifetime:19:08:44&lt;/P&gt;&lt;P&gt;  IPSEC FLOW: permit ip 10.6.0.0/255.255.0.0 host 10.10.0.97 &lt;/P&gt;&lt;P&gt;        Active SAs: 2, origin: crypto map&lt;/P&gt;&lt;P&gt;        Inbound:  #pkts dec'ed 7149 drop 0 life (KB/Sec) 4511491/3284&lt;/P&gt;&lt;P&gt;        Outbound: #pkts enc'ed 8415 drop 1 life (KB/Sec) 4512254/3284&lt;/P&gt;&lt;P&gt;  IPSEC FLOW: permit ip 10.6.0.0/255.255.0.0 host 10.10.0.97 &lt;/P&gt;&lt;P&gt;        Active SAs: 2, origin: crypto map&lt;/P&gt;&lt;P&gt;        Inbound:  #pkts dec'ed 0 drop 222 life (KB/Sec) 4534552/3104&lt;/P&gt;&lt;P&gt;        Outbound: #pkts enc'ed 222 drop 0 life (KB/Sec) 4534662/3104&lt;/P&gt;&lt;P&gt;  IPSEC FLOW: permit ip host 10.2.2.65 host 10.10.0.97 &lt;/P&gt;&lt;P&gt;        Active SAs: 2, origin: crypto map&lt;/P&gt;&lt;P&gt;        Inbound:  #pkts dec'ed 1253 drop 0 life (KB/Sec) 4390063/3254&lt;/P&gt;&lt;P&gt;        Outbound: #pkts enc'ed 1023 drop 2 life (KB/Sec) 4390036/3254&lt;/P&gt;&lt;P&gt;  IPSEC FLOW: permit ip host 10.2.2.65 host 10.10.0.97 &lt;/P&gt;&lt;P&gt;        Active SAs: 2, origin: crypto map&lt;/P&gt;&lt;P&gt;        Inbound:  #pkts dec'ed 0 drop 143 life (KB/Sec) 4428727/3103&lt;/P&gt;&lt;P&gt;        Outbound: #pkts enc'ed 143 drop 0 life (KB/Sec) 4428744/3103 &lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 11:17:55 GMT</pubDate>
    <dc:creator>Flexxx35802</dc:creator>
    <dc:date>2020-02-21T11:17:55Z</dc:date>
    <item>
      <title>2 IPSEC Flows same network?!?</title>
      <link>https://community.cisco.com/t5/network-security/2-ipsec-flows-same-network/m-p/1235317#M957717</link>
      <description>&lt;P&gt;Ok I can only think that my peer is using some sort of load balancing or something. But basically if you notice the info below for some reason there are 2 IPSEC flow's for each network. The data session dies when 1 of the IPsec flows timer expires until the other IPsec flow timer expires. After renegotiation Im good for about 57 minutes until the process repeats itself. Any suggestions is greatly appreciated. This is on a 7206 btw.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Peer: P.P.P.P/500 fvrf: (none) ivrf: (none)&lt;/P&gt;&lt;P&gt;      Phase1_id: P.P.P.P&lt;/P&gt;&lt;P&gt;      Desc: (none)&lt;/P&gt;&lt;P&gt;  IKE SA: local ME.ME.ME.ME/500 remote P.P.P.P/500 Active &lt;/P&gt;&lt;P&gt;          Capabilities:(none) connid:35 lifetime:19:08:44&lt;/P&gt;&lt;P&gt;  IKE SA: local ME.ME.ME.ME/500 remote P.P.P.P/500 Active &lt;/P&gt;&lt;P&gt;          Capabilities:(none) connid:36 lifetime:19:08:44&lt;/P&gt;&lt;P&gt;  IPSEC FLOW: permit ip 10.6.0.0/255.255.0.0 host 10.10.0.97 &lt;/P&gt;&lt;P&gt;        Active SAs: 2, origin: crypto map&lt;/P&gt;&lt;P&gt;        Inbound:  #pkts dec'ed 7149 drop 0 life (KB/Sec) 4511491/3284&lt;/P&gt;&lt;P&gt;        Outbound: #pkts enc'ed 8415 drop 1 life (KB/Sec) 4512254/3284&lt;/P&gt;&lt;P&gt;  IPSEC FLOW: permit ip 10.6.0.0/255.255.0.0 host 10.10.0.97 &lt;/P&gt;&lt;P&gt;        Active SAs: 2, origin: crypto map&lt;/P&gt;&lt;P&gt;        Inbound:  #pkts dec'ed 0 drop 222 life (KB/Sec) 4534552/3104&lt;/P&gt;&lt;P&gt;        Outbound: #pkts enc'ed 222 drop 0 life (KB/Sec) 4534662/3104&lt;/P&gt;&lt;P&gt;  IPSEC FLOW: permit ip host 10.2.2.65 host 10.10.0.97 &lt;/P&gt;&lt;P&gt;        Active SAs: 2, origin: crypto map&lt;/P&gt;&lt;P&gt;        Inbound:  #pkts dec'ed 1253 drop 0 life (KB/Sec) 4390063/3254&lt;/P&gt;&lt;P&gt;        Outbound: #pkts enc'ed 1023 drop 2 life (KB/Sec) 4390036/3254&lt;/P&gt;&lt;P&gt;  IPSEC FLOW: permit ip host 10.2.2.65 host 10.10.0.97 &lt;/P&gt;&lt;P&gt;        Active SAs: 2, origin: crypto map&lt;/P&gt;&lt;P&gt;        Inbound:  #pkts dec'ed 0 drop 143 life (KB/Sec) 4428727/3103&lt;/P&gt;&lt;P&gt;        Outbound: #pkts enc'ed 143 drop 0 life (KB/Sec) 4428744/3103 &lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:17:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/2-ipsec-flows-same-network/m-p/1235317#M957717</guid>
      <dc:creator>Flexxx35802</dc:creator>
      <dc:date>2020-02-21T11:17:55Z</dc:date>
    </item>
    <item>
      <title>Re: 2 IPSEC Flows same network?!?</title>
      <link>https://community.cisco.com/t5/network-security/2-ipsec-flows-same-network/m-p/1235318#M957718</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is the config too. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh run&lt;/P&gt;&lt;P&gt;Building configuration...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Current configuration : 3729 bytes&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;! Last configuration change at 15:45:05 CST Thu Feb 12 2009&lt;/P&gt;&lt;P&gt;! NVRAM config last updated at 11:31:25 CST Thu Feb 12 2009&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;version 12.3&lt;/P&gt;&lt;P&gt;no service pad&lt;/P&gt;&lt;P&gt;service timestamps debug uptime&lt;/P&gt;&lt;P&gt;service timestamps log uptime&lt;/P&gt;&lt;P&gt;service password-encryption&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname cisco&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot-start-marker&lt;/P&gt;&lt;P&gt;boot system flash disk0:c7200-ik9s-mz.123-4.T7.bin&lt;/P&gt;&lt;P&gt;boot-end-marker&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;enable secret 5 &lt;/P&gt;&lt;P&gt;enable password &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;clock timezone CST -6&lt;/P&gt;&lt;P&gt;syscon address 10.7.0.1 &lt;/P&gt;&lt;P&gt;syscon shelf-id 0&lt;/P&gt;&lt;P&gt;no aaa new-model&lt;/P&gt;&lt;P&gt;ip subnet-zero&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip cef&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip ssh break-string &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!         &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto isakmp policy 5&lt;/P&gt;&lt;P&gt; encr 3des&lt;/P&gt;&lt;P&gt; hash md5&lt;/P&gt;&lt;P&gt; authentication pre-share&lt;/P&gt;&lt;P&gt; group 5&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto isakmp policy 6&lt;/P&gt;&lt;P&gt; encr 3des&lt;/P&gt;&lt;P&gt; authentication pre-share&lt;/P&gt;&lt;P&gt; group 2&lt;/P&gt;&lt;P&gt; lifetime 28800&lt;/P&gt;&lt;P&gt;crypto isakmp key secret address P.P.P.P&lt;/P&gt;&lt;P&gt;crypto isakmp key secret2 address P2.P2.P2.P2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ts_peer esp-3des esp-md5-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec transform-set peer2 esp-3des esp-sha-hmac &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto map nolan local-address Serial1/0&lt;/P&gt;&lt;P&gt;crypto map nolan 10 ipsec-isakmp &lt;/P&gt;&lt;P&gt; set peer P.P.P.P&lt;/P&gt;&lt;P&gt; set transform-set ts_peer &lt;/P&gt;&lt;P&gt; set pfs group2&lt;/P&gt;&lt;P&gt; match address 101&lt;/P&gt;&lt;P&gt;crypto map nolan 15 ipsec-isakmp &lt;/P&gt;&lt;P&gt; set peer P.P.P.P&lt;/P&gt;&lt;P&gt; set transform-set ts_peer &lt;/P&gt;&lt;P&gt; set pfs group2&lt;/P&gt;&lt;P&gt; match address 102&lt;/P&gt;&lt;P&gt;crypto map nolan 20 ipsec-isakmp &lt;/P&gt;&lt;P&gt; set peer P2.P2.P2.P2&lt;/P&gt;&lt;P&gt; set transform-set peer2 &lt;/P&gt;&lt;P&gt; match address 111&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/0&lt;/P&gt;&lt;P&gt; ip address 10.7.0.1 255.255.255.0&lt;/P&gt;&lt;P&gt; ip nat inside&lt;/P&gt;&lt;P&gt; no ip mroute-cache&lt;/P&gt;&lt;P&gt; duplex full&lt;/P&gt;&lt;P&gt; no cdp enable&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Serial1/0&lt;/P&gt;&lt;P&gt; ip address ME.ME.ME.ME 255.255.255.252&lt;/P&gt;&lt;P&gt; ip nat outside&lt;/P&gt;&lt;P&gt; no ip route-cache&lt;/P&gt;&lt;P&gt; dsu bandwidth 44210&lt;/P&gt;&lt;P&gt; framing c-bit&lt;/P&gt;&lt;P&gt; cablelength 10&lt;/P&gt;&lt;P&gt; serial restart-delay 0&lt;/P&gt;&lt;P&gt; crypto map nolan&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet2/0&lt;/P&gt;&lt;P&gt; ip address 10.2.2.66 255.255.255.224&lt;/P&gt;&lt;P&gt; ip nat inside&lt;/P&gt;&lt;P&gt; no ip route-cache&lt;/P&gt;&lt;P&gt; no ip mroute-cache&lt;/P&gt;&lt;P&gt; duplex full&lt;/P&gt;&lt;P&gt; no cdp enable&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip nat inside source route-map nonat interface Serial1/0 overload&lt;/P&gt;&lt;P&gt;ip nat inside source static 10.2.2.70 X.X.X.X extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static 10.7.0.2 X.X.X.X extendable&lt;/P&gt;&lt;P&gt;ip classless&lt;/P&gt;&lt;P&gt;ip route profile&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 Serial1/0&lt;/P&gt;&lt;P&gt;ip route 10.6.0.0 255.255.0.0 10.2.2.65&lt;/P&gt;&lt;P&gt;ip route 10.8.0.0 255.255.0.0 10.2.2.65&lt;/P&gt;&lt;P&gt;ip http server&lt;/P&gt;&lt;P&gt;no ip http secure-server&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;logging trap debugging&lt;/P&gt;&lt;P&gt;logging facility local5&lt;/P&gt;&lt;P&gt;logging X.X.X.X&lt;/P&gt;&lt;P&gt;logging X.X.X.X&lt;/P&gt;&lt;P&gt;access-list 5 permit X.X.X.X&lt;/P&gt;&lt;P&gt;access-list 5 permit X.X.X.X&lt;/P&gt;&lt;P&gt;access-list 100 deny   ip host 10.2.2.65 host 10.10.0.97&lt;/P&gt;&lt;P&gt;access-list 100 deny   ip 10.6.0.0 0.0.255.255 host 10.10.0.97&lt;/P&gt;&lt;P&gt;access-list 100 deny   ip 10.8.0.0 0.0.255.255 host P2.P2.P2.P2&lt;/P&gt;&lt;P&gt;access-list 100 deny   ip host 10.2.2.65 host P2.P2.P2.P2&lt;/P&gt;&lt;P&gt;access-list 100 permit ip 10.0.0.0 0.255.255.255 any&lt;/P&gt;&lt;P&gt;access-list 101 permit ip host 10.2.2.65 host 10.10.0.97&lt;/P&gt;&lt;P&gt;access-list 102 permit ip 10.6.0.0 0.0.255.255 host 10.10.0.97&lt;/P&gt;&lt;P&gt;access-list 111 permit ip host 10.2.2.65 host P2.P2.P2.P2&lt;/P&gt;&lt;P&gt;access-list 111 permit ip 10.8.0.0 0.0.255.255 host P2.P2.P2.P2&lt;/P&gt;&lt;P&gt;access-list 111 permit ip host 10.2.2.65 host P2.P2.P2.P2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;route-map nonat permit 10&lt;/P&gt;&lt;P&gt; match ip address 100&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;control-plane&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;gatekeeper&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt; transport preferred all&lt;/P&gt;&lt;P&gt; transport output all&lt;/P&gt;&lt;P&gt; stopbits 1&lt;/P&gt;&lt;P&gt;line aux 0&lt;/P&gt;&lt;P&gt; transport preferred all&lt;/P&gt;&lt;P&gt; transport output all&lt;/P&gt;&lt;P&gt; stopbits 1&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; password&lt;/P&gt;&lt;P&gt; login&lt;/P&gt;&lt;P&gt; transport preferred all&lt;/P&gt;&lt;P&gt; transport input all&lt;/P&gt;&lt;P&gt; transport output all&lt;/P&gt;&lt;P&gt;line vty 5 15&lt;/P&gt;&lt;P&gt; password&lt;/P&gt;&lt;P&gt; login&lt;/P&gt;&lt;P&gt; transport preferred all&lt;/P&gt;&lt;P&gt; transport input all&lt;/P&gt;&lt;P&gt; transport output all&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ntp clock-period 17180052&lt;/P&gt;&lt;P&gt;ntp update-calendar&lt;/P&gt;&lt;P&gt;ntp server X.X.X.X&lt;/P&gt;&lt;P&gt;ntp server X.X.X.X&lt;/P&gt;&lt;P&gt;ntp server X.X.X.X&lt;/P&gt;&lt;P&gt;ntp server X.X.X.X&lt;/P&gt;&lt;P&gt;ntp server X.X.X.X&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco# &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Feb 2009 18:45:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/2-ipsec-flows-same-network/m-p/1235318#M957718</guid>
      <dc:creator>Flexxx35802</dc:creator>
      <dc:date>2009-02-17T18:45:14Z</dc:date>
    </item>
    <item>
      <title>Re: 2 IPSEC Flows same network?!?</title>
      <link>https://community.cisco.com/t5/network-security/2-ipsec-flows-same-network/m-p/1235319#M957719</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Why do you have two separate crypto map entries for the same peer? Why not just aggregate them into one ACL, and remove sequence 15.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Feb 2009 18:36:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/2-ipsec-flows-same-network/m-p/1235319#M957719</guid>
      <dc:creator>auraza</dc:creator>
      <dc:date>2009-02-27T18:36:18Z</dc:date>
    </item>
  </channel>
</rss>

