Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
New Member

New to IPSec, VPN, SA error..

3w6d: IPSEC(epa_des_crypt): decrypted packet failed SA identity check

What does that mean? I am very new to IPSec and dedicated vpn's, about (20minutes new :) and from

what i've read, this means that a packet that comes into my router, looks for an isakmp policy that matches the policy applied on the remote router and if it doesn't find one the tunnel isn't established... does this relate in any way to the errors about the SA?

#pkts encaps: 130, #pkts encrypt: 130, #pkts digest 130

#pkts decaps: 158, #pkts decrypt: 158, #pkts verify 158

#pkts compressed: 0, #pkts decompressed: 0

#pkts not compressed: 0, #pkts compr. failed: 0

#pkts not decompressed: 0, #pkts decompress failed: 0

#send errors 0, #recv errors 0

but this says no errors have been logged so where are these errors coming from? and the tunnel is up by the way...

Thanks.

3 REPLIES
Silver

Re: New to IPSec, VPN, SA error..

You have not mentioned if you are using a 7200 router. Buy this seems to be a standard bug in 7200 router.

New Member

Re: New to IPSec, VPN, SA error..

cisco 2611 router

New Member

Re: New to IPSec, VPN, SA error..

please show your config...

461
Views
0
Helpful
3
Replies
CreatePlease to create content