cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
651
Views
0
Helpful
2
Replies

Anti-replay window size

Ruterford
Level 1
Level 1

Hello,
We would like to increase the anti-replay window size on our ISR routers connected to ASR using DMVPN. On ISR I can use up to 1024, but ASR only limited to 512.
I am wondering if I can configure two different window sizes on ISRs - 1024 and ASR- 512, connected to each other via DMVPN, with no implications/problems. (I believe 512 should be enough for ASR side but ISR would need more).

Thanks!

1 Accepted Solution

Accepted Solutions

Marcin Latosiewicz
Cisco Employee
Cisco Employee

Yes you can have separate anit-replay windows sizes - the check is local and only done in inbound direction.

Now what you might want to remember is that enabling this feature will not imply existing connections will start using the new windows straight away.

View solution in original post

2 Replies 2

Marcin Latosiewicz
Cisco Employee
Cisco Employee

Yes you can have separate anit-replay windows sizes - the check is local and only done in inbound direction.

Now what you might want to remember is that enabling this feature will not imply existing connections will start using the new windows straight away.

Thanks Marcin,

The SA will need to re-establish for anti-replay to kick in.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: