%CRYPTO-4-RECVD_PKT_MAC_ERR: decrypt: mac verify failed
I am receiving the following error when I try to establish an IPSEC tunnel in one of our branch .
*Jan 19 14:16:37.059: %CRYPTO-4-RECVD_PKT_MAC_ERR: decrypt: mac verify failed for connection id=2009 local=172.16.16.6 remote=172.16.16.1 spi=4A4D2438 seqno=000023E2 *Jan 19 14:16:53.627: %DUAL-5-NBRCHANGE: IP-EIGRP(0) 60: Neighbor 172.16.16.1 (FastEthernet0/0) is down: Peer goodbye received *Jan 19 14:16:55.591: %DUAL-5-NBRCHANGE: IP-EIGRP(0) 60: Neighbor 172.16.16.1 (FastEthernet0/0) is up: new adjacenc branch is connected with two Wan providers. eigrp is in place in order to switch traffic in case of fail
According to CCO this message means
. %CRYPTO-4-RECVD_PKT_MAC_ERR: decrypt: mac verify failed for connection id=[dec]
The MAC verify processing failed. This may be caused by the use of the wrong key by either party during the MAC calculations. This activity could be considered a hostile event.
I have checked and double checked the key . It seems OK .
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
Table of Contents Introduction:This document describes details on how
NAT-T works. Background: ESP encrypts all critical information,
encapsulating the entire inner TCP/UDP datagram within an ESP header.
ESP is an IP protocol in the same sense that TCP an...