cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
536
Views
0
Helpful
2
Replies

IPSec VPN and CEF load-balance per packet

Hi all,

I am having problems with CEF load balancing and a pair of VPN IPSec tunnels. Basically I have 2 serial links and I am load balancing between the 2 of them in a per packet fashion without IPSec enabled on the serial links and everything works fine. When I applied the crypto maps on the serial interfaces the load balancing stops working and all the traffic goes only over one of the serial links. I have tried different IOS versions (12.4(3g), 12.4(13), 12.3(22) with the same issue, I was wondering if I have something wrong in the config, I am attaching some outputs.

2 Replies 2

didyap
Level 6
Level 6

It look like , you hitting the bug:CSCeb03516.

Workaround: Configure GRE tunnels, then route this traffic over a crypto enabled interface that encrypt this traffic. 'ip

load-sharing per-packet' will be configured on the tunnel and crypto interface.

Hi didyap,

I am not able to find that bug ID (CSCeb03516), could you send me the link or the bug description?

regards!

vicente