Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for
Search instead for
Did you mean:
The user recieves the %CRYPTO-4-PKT_REPLAY_ERR: decrypt: replay check failed error message with multi-point GRE and when an IPSec tunnel is built between two routers
This issue is documented in Cisco bug ID CSCeg43855
A router that encrypts packets can send locally-originated traffic out of order after the packets are encrypted. Locally-originated traffic includes keepalive packets and routing updates. This scenario results in the failure of anti-replay checks.
Anti-replay is a security service in which the receiver can reject old or duplicate packets in order to protect itself against replay attacks.
In this case, anti-replay check failure causes the recipient router to drop packets that are out of order. This problem occurs when a multipoint GRE (mGRE) and IPSec tunnel is built between two routers.