10-07-2005 08:05 AM - edited 02-21-2020 02:01 PM
I have a site to site vpn between a pix firewall and a sonicwall firewall. I am receiving this message on the pix:
IPSEC(sw_esp_decap): fail antireplay check
IPSEC(cipher_ipsec_request): decap failed for x.x.x.x -> x.x.x.x
Does anyone know what this means? Thanks for the help.
10-13-2005 08:13 AM
It appears to be a IPSec policy mismatch between the two firewalls. IPSec on PIX firewalls support "anti-replay" services if IKE is enabled on the PIX. I would suggest you to verify if the remote end supports this feature.
10-13-2005 11:48 PM
Hello ,
It seems u have enabled PFS on one PIX & haven't enabled on other Unit.
Either enable on both end or disable PFS on both end.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide