Loading...
Loading...
While trying to negotiate the tunnel, multiple IPSEC SAs are created. This increases the tunnel count, but the tunnels are not in a working state.
IPSEC traffic is disrupted.
-- Use wildcard ips for source/destination address in traffic selector. -- Change the destination address to a specific address.
Keep responder's IKE peer as passive so that it can never be an initiator.
The issue occurs because next hops are not refreshed in case of traffic narrowing. (changing of destination address from wildcard to specific) Make explicit calls to refresh next hops in case of narrowing.
Click on a version to see all relevant bugs
F5 Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.