12-26-2013 07:26 AM
Hello,
We would like to increase the anti-replay window size on our ISR routers connected to ASR using DMVPN. On ISR I can use up to 1024, but ASR only limited to 512.
I am wondering if I can configure two different window sizes on ISRs - 1024 and ASR- 512, connected to each other via DMVPN, with no implications/problems. (I believe 512 should be enough for ASR side but ISR would need more).
Thanks!
Solved! Go to Solution.
12-27-2013 02:30 AM
Yes you can have separate anit-replay windows sizes - the check is local and only done in inbound direction.
Now what you might want to remember is that enabling this feature will not imply existing connections will start using the new windows straight away.
12-27-2013 02:30 AM
Yes you can have separate anit-replay windows sizes - the check is local and only done in inbound direction.
Now what you might want to remember is that enabling this feature will not imply existing connections will start using the new windows straight away.
12-27-2013 08:41 AM
Thanks Marcin,
The SA will need to re-establish for anti-replay to kick in.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide