QuestionQ13

Troubleshooting using ASDM and CLI

Question Image

Refer to the exhibit. After a tunnel is configured between two sites, users report that connections to applications across the VPN do not work consistently.

The output from show crypto ipsec sa was captured on one of the VPN devices. Based on this output, what should be done to resolve the issue?

Explanation

A large received replay-failure count means the IPsec anti-replay check is discarding packets whose sequence numbers fall outside its acceptable window. Increasing or otherwise adjusting the IPsec replay window accommodates packet reordering and prevents those packets from being dropped.

Community Discussion

No comments yet. Be the first to start the discussion!