Cisco Ipsec Tweaks :
crypto isakmp keepalive 15 10
!
crypto map securewan 1 ipsec-isakmp
set security-association lifetime kilobytes 18432000
set security-association lifetime seconds 86400
set security-association idle-time 7200
!
If your replay window size has not been set to a number that is high enough for the number of packets received, you will receive a system message such as the following:
*Nov 17 19:27:32.279: %CRYPTO-4-PKT_REPLAY_ERR: decrypt: replay check failed connection id=1
The above message is generated when a received packet is judged to be outside the anti-replay window.
Additional Notes:
If there’s no interruption of service, it could just be a normal and temporary condition, especially if the SAs (IPSEC tunnels) are still being established.
Otherwise, I suggest setting the anti-replay window to, say, 1024.
crypto ipsec security-association replay window-size 1024
Additional Notes:
set security-association idle-time
IPsec SA idle timer allows SAs associated with inactive peers to be deleted after given time expires, thus allowing more resources will be available to create new SAs as required.
When a router running the Cisco IOS software creates an IPsec security association (SA) for a peer, resources must be allocated to maintain the SA. The SA requires both memory and several managed timers. For idle peers, these resources are wasted. If enough resources are wasted by idle peers, the router could be prevented from creating new SAs with other peers. The IPsec Security Association Idle Timers feature introduces a configurable idle timer to monitor SAs for activity, allowing SAs for idle peers to be deleted. Benefits of this feature include:
•
Increased availability of resources
•
Improved scalability of Cisco IOS IPsec deployments
set security-association idle-time 7200
The IPsec SA idle timers are different from the global lifetimes for IPsec SAs. The expiration of the global lifetime is independent of peer activity. The IPsec SA idle timer allows SAs associated with inactive peers to be deleted before the global lifetime has expired.
If the IPsec SA idle timers are not configured, only the global lifetimes for IPsec SAs are applied. SAs are maintained until the global timers expire, regardless of peer activity.
Comments
(There are currently no comments for this post.)