cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
401
Views
3
Helpful
2
Replies

CSCvn31824 - %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet h

Does anybody know if CSR 8000V with IOS XE 17.06.03a is also affected by this bug?
I have severals flapping VPN tunnels and was wondering if this was the root cause.

2 Replies 2

Lorena783lopez
Level 1
Level 1

The Cisco CSR 8000V is a virtual router platform, and the bug you mentioned could potentially affect it if the specific software version you're running matches the affected versions mentioned in reports or advisories.

To determine if your CSR 8000V with IOS XE 17.06.03a is affected by the bug causing flapping VPN tunnels, you can take these steps:

  • Check Cisco Advisories: Visit the Cisco Security Advisories and Alerts page or the Cisco Bug Search Tool. Search for any known issues or bugs related to VPN tunnels and IOS XE 17.06.03a. Cisco often publishes information about known bugs, their impact, and recommended actions.
  • Review Release Notes: Check the release notes for IOS XE 17.06.03a. Cisco usually documents any critical bugs or issues addressed in each software release. Look for mentions of VPN stability or tunnel flapping fixes.
  • Consult Cisco Support: If you have a Cisco support contract, reach out to Cisco's technical support team. Provide them with details about your specific setup, including the CSR 8000V model, software version, and symptoms of VPN tunnel flapping. They can investigate further and provide guidance or confirm if the bug affects your configuration.
  • Monitor Logs and Diagnose: In the meantime, monitor your router logs for any relevant messages related to VPN tunnels or connectivity issues. Diagnose the flapping VPN tunnels to see if there are any patterns or specific triggers causing the instability.  
  • Consider Software Upgrade: If there is confirmation that your software version is affected by a known bug causing VPN tunnel flapping, consider upgrading to a newer, more stable software version recommended by Cisco.

By following these steps and leveraging Cisco's resources, you can gain a better understanding of whether the bug you mentioned is the root cause of your VPN tunnel flapping issues on the CSR 8000V with IOS XE 17.06.03a.

GM Socrates Login

 

 

 

Yes sure 

When VPN is flapping the iosec spi is remove from one end and still used by other end 

The peer that still used it send packet with SPI remove from this end abd hence you get this error.

Only solve the flapping IPsec abd this error will be not show anymore 

MHM