cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1343
Views
0
Helpful
4
Replies

Crypto Error - %CRYPTO-4-RECVD_PKT_MAC_ERR (x1):

kdelhi_ganesh
Level 1
Level 1

Hi Network Folks,

Please help me here, searching for your help.Here is the scenrio.

We have IPSEC over GRE tunnel between End A to End B.

I am receiving continious error in End A router - 2821.

Pls find the below logs.

Feb 24 01:32:43 UTC: %CRYPTO-4-RECVD_PKT_MAC_ERR: decrypt: mac verify failed for connection id=3002 local=1.1.1.1 remote=2.2.2.2 spi=A787F8E5 seqno=00000174

I have tried rebuild the tunnel at both the end but no luck, can anybody suggest for the above errors.Awaiting anxiously

4 Replies 4

Ivan Martinon
Level 7
Level 7

On the router that logs these messages, can you increase the replay window size?

Hi,

Sorry for the delayed reply;Infact there is no production issue because of this errors.

Thank you all for replying me for the above issue, i got the advice from TAC saying " THIS IS THE KNOW ISSUE AND NEED TO DOWNGRADE THE IOS"

Thanks,

Ganesh

auraza
Cisco Employee
Cisco Employee

This error basically means that the packet failed authentication.

You can try disabling the hardware crypto engine and see if that makes the error go away:

no crypto engine accelerator

If the error doesn't go away and it changes to a different error, it could mean that packets are getting corrupted in transit, and thus failing authentication.

Hi,

Sorry for the delayed reply;Infact there is no production issue because of this errors.

Thank you all for replying me for the above issue, i got the advice from TAC saying " THIS IS THE KNOW ISSUE AND NEED TO DOWNGRADE THE IOS"

Thanks,

Ganesh

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: