cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

Welcome to Cisco Firewalls Community


257
Views
0
Helpful
4
Replies
Highlighted
Beginner

VPN Decaps and Decrypts

Hi Everyone,

Any idea what could be causing this?

 

#pkts encaps: 1181, #pkts encrypt: 1181, #pkts digest: 1181
#pkts decaps: 1181, #pkts decrypt: 0, #pkts verify: 0

 

we usually encounter encaps/encrypts are incrementing, but no decaps/encrypt -- usually is nat issue, but this one is different.

 

Advance thanks

 

 

Everyone's tags (1)
2 ACCEPTED SOLUTIONS

Accepted Solutions
VIP Advisor

Re: VPN Decaps and Decrypts

Look at both the device log output and compare config, This could happen when there's a route problem, NAT problem, or some sort of VPN filter.

 

Check the tunnel configuration on both the devices  and check the is the Tunnel up ?

 

show crypto isakmp sa
show crypto ipsec sa
BB
*** Rate All Helpful Responses ***
VIP Advisor

Re: VPN Decaps and Decrypts

Make sure that return traffic is routed over the crypto interface. Also,
run a packet trace while the SA is up to see of the return packet will get
encrypted by responding device or not
4 REPLIES 4
VIP Advisor

Re: VPN Decaps and Decrypts

Look at both the device log output and compare config, This could happen when there's a route problem, NAT problem, or some sort of VPN filter.

 

Check the tunnel configuration on both the devices  and check the is the Tunnel up ?

 

show crypto isakmp sa
show crypto ipsec sa
BB
*** Rate All Helpful Responses ***
Beginner

Re: VPN Decaps and Decrypts

Hi,
It worked after we reconfigured and retyped the corresponding tunnel-group.. exactly the same.
We are using pre-shared key, not sure it was the key, but a mismatched key should be visible in the debug, and tunnel should not form from the start. This one the tunnel stood up and was stable, it's just the decrypt is not incrementing
Thanks for the input though
VIP Advisor

Re: VPN Decaps and Decrypts

Make sure that return traffic is routed over the crypto interface. Also,
run a packet trace while the SA is up to see of the return packet will get
encrypted by responding device or not
Beginner

Re: VPN Decaps and Decrypts

Hi,
It worked after we reconfigured and retyped the corresponding tunnel-group.. exactly the same.
We are using pre-shared key, not sure it was the key, but a mismatched key should be visible in the debug, and tunnel should not form from the start. This one the tunnel stood up and was stable, it's just the decrypt is not incrementing
Thanks for the input though