Loading...
Loading...
In a policy based IPSec s2s tunnel setup , intermittently the traffic across a VPN tunnel unexpectedly stops working after some days of correctly passing the traffic. The IKE Tunnel remains up and affects individual SA. Below errors are seen under ikev2 debugs: IKEv2-PROTO-4: (2815): Processing CREATE_CHILD_SA exchange IKEv2-PROTO-7: (2815): Duplicate IPsec SA detected.
Issue is seen on FP3120 running FTD version 7.4.2.1.The IKE Tunnel remains up and affects individual SA.
the lifetime of the IPsec SA on the local FTD was reduced from 3600 seconds to 3000 seconds which resolved the issue.
To confirm this issue, below logs are suggested to be collect when issue is occurring: show crypto ikev2 sa detail show crypto ipsec sa inactive show asp table classify crypto show asp table vpn-context detail Show counters before and after the issue (collected on both devices). show counters debug menu ikev2 8 0 debug menu ikev2 9 0 debug menu ikev2 12 1 debug menu ikev2 13 0 debug menu ikev2 14 0 debug menu ikev2 3 1 show crypto ipsec sa peer detail show vpn-sessiondb detail l2l filter ipaddress Enable the debug logs in both end local and peer. 1. debug crypto condition peer 2. debug crypto ikev2 proto 255 3. debug crypto ikev2 plat 255 4. debug crypto ipsec 255 These debugs can be resource-intensive and should be redirected to a syslog server. The debugs should be disabled once information is collected.
Click on a version to see all relevant bugs
Cisco Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.