ā08-06-2024 06:45 AM
Hi Team ,
We are observing low speed while coping data from client infra via IPSEC Tunnel.
We have seen below errors in router where IPSEC is configured.
%VPN_HW-1-PACKET_ERROR: slot: 0 Packet Encryption/Decryption error, Decr Replay Chk Failure:srcadr=XX.XX.XX.XX ,dstadr=XX.XX.XX.XX,size=144,sequence number=0x74F5,SPI=0x76974E6B
Can any one confirm what exactlty cause of getting packets out of order and how can we solve this.
ā08-06-2024 07:02 AM
What is platform you have ?
MHM
ā08-06-2024 07:36 AM
Cisco 1941
ā08-06-2024 07:40 AM
ā08-06-2024 09:55 AM
Thanks for sharing the document.
There is o Qos policy enabled in the datapath.But still we are getting the same error logs.Could you please suggest on this.
ā08-06-2024 10:17 AM
You meaning there is NO QoS'
Friend check path' it can you have two path and this make packet receive out or order.
To detect multi path use traceroute and see hops appear
MHM
ā08-07-2024 09:26 PM
I am seeing the Router egress port is supporting 100Mbps speed and there are some output drops happening on the same interface which is more than 2%.I am suspecting this is causing replay check failure.Please let me know your thoughts.
ā08-06-2024 07:02 AM
The error indicates a replay check failure, often caused by packet duplication or incorrect sequencing. To address this, check your IPSEC configuration for correct settings and ensure that both ends of the tunnel are synchronized. Verify that your devices have matching security policies and try updating firmware if issues persist.
ā08-06-2024 07:36 AM
This is the IPSEC between Cisco 1941 routers.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide