PIX 515E with release 7.1. I have lan to lan vpn (3DES-MD5). It works perfect but if I have a disconnect by timeout or shutdown from the other side; sometimes I see that in the VPN tunnel the TX bytes is in
Mean while I can see the RX counters incrementing.
The tunnel its perfectly established; phase 1 and phase 2 without errors nor warnings.
But in ASDM, while monitoring the VPN, the TX bytes stay at 0 and the RX increment ok.
any ideas.
Im thinking about a bug in this PIX release :(
Didn't find your answer? Ask the community — no account required.
L
Lutz Donnerhacke
Are both IPSec SAs available? It looks like the classic blackhole effect.
X
XaBi
Yes, they are available; I have phase 1 and phase 2 completed.
whats the blackhole effect?
thanks
L
Lutz Donnerhacke
Does "show crypto ipsec sa" report two active SAs?
The data channels of IPSec are on-way, that's why there are at least two. If the receiver side forget the SA, the received data is silently dropped (as required by the standard). There is not way to determine this loss of data than looking on the SAs on both sides.
Usually this effect does not occur, because the control channel (phase 1) is used to inform the other side about the drop of any SA. Unfortunly the control channel is vulnerable to loss of packets ...
X
XaBi
hi!
here is the output of the ipsec sa; look at the encapsulation counters as 0; thats the 0 bytes TX. (removed the public peer ip with *.*.*.*):
Crypto map tag: VPNmap, seq num: 130, local addr: EXTMARMEDSA
access-list extranet_cryptomap_130 permit ip 10.0.0.0 255.0.0.0 INTSANTANDER 255.255.0.0 local ident (addr/mask/prot/port): (10.0.0.0/255.0.0.0/0/0) remote ident (addr/mask/prot/port): (INTSANTANDER/255.255.0.0/0/0) current_peer: 88.2.173.40