cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
795
Views
0
Helpful
1
Replies

IPSEC traffic TX & RX - what causes the count reset?

lchance
Level 1
Level 1

Does anyone know what causes the count to reset on TX and RX in ASDM?

I've been troubleshooting this tunnel and notice the TX and RX numbers when change ever so often.

You can see here where TX/RX 293119/3086180 reset to TX/RX 2954/9646

BEFORE

A2950 - 04143 TX-RX before.jpg

and

AFTER

A2950 - 04146 TX-RX after.jpg

1 Reply 1

Marcin Latosiewicz
Cisco Employee
Cisco Employee

Hi,

I will not answer your question fully, but I guess someone who knows can jump in.

ASDM display is based on "show vpn-sessiondb" output.

There is a chance that the counters you have are directly derived from IPsec SA liftime bytes. I.e. if liftime bytes expire, there is a phase 2 renegotiation which might cause the counters to reset.

Monitoring "show vpn-sessiondb detail remote" and "show crypto ipsec sa peer IP_ADD_RE_SS" would be a way to confirm ;-)

Marcin