Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Cisco > more detail in IPSEC debugging?

Reply
Thread Tools

more detail in IPSEC debugging?

 
 
Rob
Guest
Posts: n/a
 
      10-03-2012
We have several IPSEC tunnels to all kinds of different routers.
When I enable "debug crypto ipsec" I get occasional messages like this:

IPSEC(epa_des_crypt): decrypted packet failed SA identity check

I know what it means and how to solve it, but unfortunately there
is no reference to what SA it is related to.

Is there really no way to get this information?
Anything pointing to the source of the problem would be welcome...
(remote IP address, SA number, etc)
 
Reply With Quote
 
 
 
 
Rob
Guest
Posts: n/a
 
      10-07-2012
jwil <> wrote:
> Try debug crypto isakmp
>
>
> On 03 Oct 2012 07:41 AM ,Rob <> wrote:
>> We have several IPSEC tunnels to all kinds of different routers.
>> When I enable "debug crypto ipsec" I get occasional messages like this:
>>
>> IPSEC(epa_des_crypt): decrypted packet failed SA identity check
>>
>> I know what it means and how to solve it, but unfortunately there
>> is no reference to what SA it is related to.
>>
>> Is there really no way to get this information?
>> Anything pointing to the source of the problem would be welcome...
>> (remote IP address, SA number, etc)


Sorry but isakmp is not related to these errors...

 
Reply With Quote
 
 
 
 
Rob
Guest
Posts: n/a
 
      10-08-2012
jwil <> wrote:
> Is this a router or Firewall?
>
> Debug crypto isakmp and ipsec are both good ways to find out why the tunnel is not working or has errors. They just work for different phases of the tunnel. Maybe you should try to use a higher level of debug i.e debug crypto ipsec 100.


It is a router.
100 is not a valid option for debug crypto ipsec.
That is exactly the kind of thing I am looking for: some option to
have more debug output. But I cannot find it.

I have only this message:
IPSEC(epa_des_crypt): decrypted packet failed SA identity check

I know what it means but I want to know what is the packet that is not
matching so that I can change the access list on the correct peer.
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
cisco VPN ipsec tunnel virtual interface operation detail question ricecs@gmail.com Cisco 3 07-29-2006 07:11 PM
ASp.net data binding: Master-detail-detail Frederik Borg ASP .Net Datagrid Control 0 06-09-2006 11:41 AM
Counters under "show crypto ipsec sa detail" Rod Cisco 0 05-02-2004 02:40 PM
IPSec vs. L2TP/IPsec vs. PPTP David Cisco 0 01-07-2004 04:03 AM
Master Detail detail Arun Kumar Menon ASP .Net Datagrid Control 0 08-06-2003 08:04 PM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57