cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1005
Views
10
Helpful
4
Replies

Break in tunnel - IPSEC

jewedo828417539
Level 1
Level 1

Hi all,

 

I have these 2 questions looming in my mind for some time. Please throw some light on these.

1. Can the terms SA and tunnel  be used interchangeably?

2. What is the exact purpose of doing a'a crypto ipsec sa'? Can we say that it is done due to a 'break in tunnel'?

 

Thanks in advance

2 Accepted Solutions

Accepted Solutions

Joseph W. Doherty
Hall of Fame
Hall of Fame

#1 I don't believe so.  IPSec might be used to encrypt, for example, a whole packet, which in turn, is encapsulated within another packet.  The encapsulation, not the encryption, would be what would constitute the tunnel.

Or, for example, a packet's data segment, alone, might be encrypted, but the whole packet is not, so no encapsulation and so no tunnel.

BTW, on Cisco routers you can define GRE/IPSec tunnels in either "transport" or "tunnel" mode.  See https://www.ciscopress.com/articles/article.asp?p=25477 

#2 Do you mean "show crypto ipsec sa"?  If so, it show information about ipsec session(s).  Unsure what you mean by "break", unless by it showing that a session isn't active.

View solution in original post

Ah well, if a IPSec session isn't working, not passing traffic, checking the SA session status would show whether the session appears to be up.  If not, then there's some problem between the SA peers.  Possibly a lost in network connectivity between the peers, or perhaps something like the session key has been changed on one side and not the other.  So, in that sense, using this show command would help debug/detect a "break".

If the SA session looks good, but there's still no passing traffic, perhaps there's some other problem other than IPSec issues.

Tunneling Protocol (better than what I might briefly write)

View solution in original post

4 Replies 4

Joseph W. Doherty
Hall of Fame
Hall of Fame

#1 I don't believe so.  IPSec might be used to encrypt, for example, a whole packet, which in turn, is encapsulated within another packet.  The encapsulation, not the encryption, would be what would constitute the tunnel.

Or, for example, a packet's data segment, alone, might be encrypted, but the whole packet is not, so no encapsulation and so no tunnel.

BTW, on Cisco routers you can define GRE/IPSec tunnels in either "transport" or "tunnel" mode.  See https://www.ciscopress.com/articles/article.asp?p=25477 

#2 Do you mean "show crypto ipsec sa"?  If so, it show information about ipsec session(s).  Unsure what you mean by "break", unless by it showing that a session isn't active.

Thanks. In the second question, what I meant was whether 'clear crypto ipsec sa' is done due to a 'break in tunnel'

Also, could you elaborate a little on what you said about what constitutes a tunnel? (You mentioned it is the encapsulation, not the encryption what constitutes a tunnel. I couldn't really catch that.)

Thanks in advance

Ah well, if a IPSec session isn't working, not passing traffic, checking the SA session status would show whether the session appears to be up.  If not, then there's some problem between the SA peers.  Possibly a lost in network connectivity between the peers, or perhaps something like the session key has been changed on one side and not the other.  So, in that sense, using this show command would help debug/detect a "break".

If the SA session looks good, but there's still no passing traffic, perhaps there's some other problem other than IPSec issues.

Tunneling Protocol (better than what I might briefly write)

Thanks Mr. Doherty.