cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2383
Views
0
Helpful
2
Replies

IPSEC tunnel drop

mandar1607
Level 1
Level 1

I have cisco 1841 Software (C1841-ADVIPSERVICESK9-M), Version 12.4(25f) router IPSEC tunnel intermittently get dropped.

 

Following are error message

 

%CRYPTO-3-IKE_PAK_IN_Q_TIME_LIMIT_EXCEED: Pak spent too much time in the IKE input queues

%CRYPTO-6-IKMP_MODE_FAILURE: Processing of Main mode failed with peer at X.X.X.X 
%CRYPTO-4-IKMP_NO_SA: IKE message from X.X.X.X has no SA and is not an initialization offer

 

Looking at CPU utilization I see following .

 

                                                             
    333333333333333333333333333333333333333333333333333333333333
    999888889999988888888885555544444777777777777777666669999955
100                                                             
 90                                                             
 80                                                             
 70                                                             
 60                                                             
 50                                                             
 40 ****************************     ***************************
 30 ************************************************************
 20 ************************************************************
 10 ************************************************************
   0....5....1....1....2....2....3....3....4....4....5....5....6
             0    5    0    5    0    5    0    5    0    5    0
               CPU% per second (last 60 seconds)

                                                                
    345444445544444444444664444444445555556655665675567444445444
    910720460000253234670115430513008784890095017337892937418335
100                                                             
 90                                                             
 80                                                             
 70                                               *  **         
 60                      **         *** ***************     *   
 50   **   ***   *    ** ***   *    ###################* *  *  *
 40 ############################################################
 30 ############################################################
 20 ############################################################
 10 ############################################################
   0....5....1....1....2....2....3....3....4....4....5....5....6
             0    5    0    5    0    5    0    5    0    5    0
               CPU% per minute (last 60 minutes)
              * = maximum CPU%   # = average CPU%

                  1 1    1      11111                                       
    768677876857550906678057458900000885867599765576597678785897667695865577
    306861855247050701216057929400000705627299421491827301481867525897037531
100               ***    *      *##**       **                *     *       
 90   *   *       ***   **    **###***  *   **       *     * **     *       
 80   * * ** * *  ***   ** *  *#####*** * * **    *  **  * * ***  * * *     
 70 * ******** *  #**  *** *  *#####*** * * ***   *  ** **** **** *** *   **
 60 ********** * *#*#*******  *#####******* ****  ********** ***************
 50 **************###**********######********#******************************
 40 ########################################################################
 30 ########################################################################
 20 ########################################################################
 10 ########################################################################
   0....5....1....1....2....2....3....3....4....4....5....5....6....6....7..
             0    5    0    5    0    5    0    5    0    5    0    5    0  
                   CPU% per hour (last 72 hours)
                  * = maximum CPU%   # = average CPU%

 

could you please help in isolating issue.

2 Replies 2

Hi,

You can see this information:

 

  • Routers without Call Admission Control for IKE 
    If the IKE process is under heavy load, incoming IKE packets may spend too much time in the IKE input queue which will result in the generation of a error level (severity 3) Syslog message. The Syslog message is %CRYPTO-3-IKE_PAK_IN_Q_TIME_LIMIT_EXCEED which has this format:
    %CRYPTO-3-IKE_PAK_IN_Q_TIME_LIMIT_EXCEED : Pak spent too much time in the IKE input queues 
    Additional information on those syslog messages can be found at http://www.cisco.com/en/US/docs/ios/12_3t/system/messages/smg2tmsd.html#wp715560.
    All %CRYPTO-3-IKE_PAK_IN_Q_TIME_LIMIT_EXCEED messages should be investigated to determine if this issue is being exploited.

Do you have a ISM module to encrypt the traffic, or you are using the built-in crypto engine to encrypt the traffic? (show inventory) would show the hw modules.

 

David castro,

 

Regards

 

 

http://www.cisco.com/c/en/us/support/docs/csr/cisco-sr-20060726-ike.html