...
SD-WAN BFD session down because of IPSec anti-replay packet drops.
This issue is likely observed when NAT session flap or the peer router get reloaded.
Manually do IPsec rekey from remote end via "request platform software sdwan security ipsec-rekey" to reset SPI sequence number.
IPSec SA receives anti-replay error and SD-WAN BFD session get stuck into down state because of all of IPsec packets getting dropped for one direction.
Cisco Integration
Learn more about where this data comes from
Bug Scrub Advisor
Streamline upgrades with automated vendor bug scrubs
BugZero Enterprise
Wish you caught this bug sooner? Get proactive today.