GRE over IPsec tunnel intermittently being cut off

Unanswered Question
May 29th, 2008
User Badges:

I need a little help here. I am using DMVPN between HO and branches and one branch's VPN always got cut off several times a day for no reason. Here is part of the output of "show crypto ipsec sa"


#pkts encaps: 13701214, #pkts encrypt: 13701214, #pkts digest: 13701214

#pkts decaps: 9495499, #pkts decrypt: 9495499, #pkts verify: 9495499

#pkts compressed: 139621, #pkts decompressed: 612287

#pkts not compressed: 13547522, #pkts compr. failed: 14071

#pkts not decompressed: 8883212, #pkts decompress failed: 0

#send errors 5, #recv errors 0


I compared it with other routers and they have way less "#pkts compr. failed". Will this be the problme? What does it mean? Where can I find the explaination for counters in the output?


There is also no related records at all in the buffer loggings. The logging is configured to log debbuging level.


The reason why I say it's the VPN not the internet get cut off is because I am using ping monitor and when it's cut off I can still ping the router's interface but not the tunnel interface. Anyone please help! Thanks!



  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
aghaznavi Wed, 06/04/2008 - 08:58
User Badges:
  • Silver, 250 points or more

verify the current configuration of the router where you see this compression failed packets and fix the issue.

Actions

This Discussion