cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
188
Views
0
Helpful
0
Replies
bgandhi
Beginner

Site-to-Site encryption failure for single subnet

HI All,

Have been facing intermittent problem. have Cisco 7200 with NPE-G2 and VAm2+. It is primarily encryption router. It has around 700+ sites establishing tunnels to this router. Each site would have 3-4 ACL to match on single peering.

Problem statement is as follows.

Out of 3-4 ACLs one ACL matches do not get encrypted on central router. This also happens randomly with few branches. Typically one subnet does not get encrypted at DC and decrypted at Branch. Rest all work fne. The frequency of this issues is 12-16 hrs.

Have done debug IP packet for affected branch and routing seems to be happening fine. Seems traffic does not get aligned to right SA. How to check the same?

Also. please  guide if some other troubleshooting steps to be followed.

Regards,

Bhavesh

0 REPLIES 0
Content for Community-Ad