04-21-2015 12:08 AM - edited 02-21-2020 08:11 PM
I have cisco 1841 Software (C1841-ADVIPSERVICESK9-M), Version 12.4(25f) router IPSEC tunnel intermittently get dropped.
Following are error message
%CRYPTO-3-IKE_PAK_IN_Q_TIME_LIMIT_EXCEED: Pak spent too much time in the IKE input queues
%CRYPTO-6-IKMP_MODE_FAILURE: Processing of Main mode failed with peer at X.X.X.X
%CRYPTO-4-IKMP_NO_SA: IKE message from X.X.X.X has no SA and is not an initialization offer
Looking at CPU utilization I see following .
333333333333333333333333333333333333333333333333333333333333
999888889999988888888885555544444777777777777777666669999955
100
90
80
70
60
50
40 **************************** ***************************
30 ************************************************************
20 ************************************************************
10 ************************************************************
0....5....1....1....2....2....3....3....4....4....5....5....6
0 5 0 5 0 5 0 5 0 5 0
CPU% per second (last 60 seconds)
345444445544444444444664444444445555556655665675567444445444
910720460000253234670115430513008784890095017337892937418335
100
90
80
70 * **
60 ** *** *************** *
50 ** *** * ** *** * ###################* * * *
40 ############################################################
30 ############################################################
20 ############################################################
10 ############################################################
0....5....1....1....2....2....3....3....4....4....5....5....6
0 5 0 5 0 5 0 5 0 5 0
CPU% per minute (last 60 minutes)
* = maximum CPU% # = average CPU%
1 1 1 11111
768677876857550906678057458900000885867599765576597678785897667695865577
306861855247050701216057929400000705627299421491827301481867525897037531
100 *** * *##** ** * *
90 * * *** ** **###*** * ** * * ** *
80 * * ** * * *** ** * *#####*** * * ** * ** * * *** * * *
70 * ******** * #** *** * *#####*** * * *** * ** **** **** *** * **
60 ********** * *#*#******* *#####******* **** ********** ***************
50 **************###**********######********#******************************
40 ########################################################################
30 ########################################################################
20 ########################################################################
10 ########################################################################
0....5....1....1....2....2....3....3....4....4....5....5....6....6....7..
0 5 0 5 0 5 0 5 0 5 0 5 0
CPU% per hour (last 72 hours)
* = maximum CPU% # = average CPU%
could you please help in isolating issue.
04-21-2015 09:24 AM
Hi,
You can see this information:
Do you have a ISM module to encrypt the traffic, or you are using the built-in crypto engine to encrypt the traffic? (show inventory) would show the hw modules.
David castro,
Regards
04-21-2015 09:26 AM
http://www.cisco.com/c/en/us/support/docs/csr/cisco-sr-20060726-ike.html
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide