cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
589
Views
10
Helpful
3
Replies

Getting CRYPTO-4-PKT_REPLAY_ERR replay check failed message

Patrick McHenry
Level 3
Level 3

Hi,

In dynamips I created a GRE tunnel over a VPN between 2 routers over a simulated Internet connection and it works great. I'm able to create EIGRP neighborships, exchange routes and ping across it all day without losing a ping.

Next, I created a l2TPv3 tunnel across the VPN to have a VLAN existing on both sides. Shortly after sending traffic across the l2TPv3 tunnel, the EIGRP neighborship fails, the tunnel breakes, and I start losing pings. The tunnel will then re-establish and the fail again and again and my pings will fail and succeed for a bit then fail.

Console message:

%CRYPTO-4-PKT_REPLAY_ERR replay check failed

From looking around for work-arounds I've increased the crypto ipsec security-association replay window-size to 1028 and used encryption only on both sides of the VPN but, still the tunnel breaks.

See attached diagram.

Any suggestions?

Thank you, Pat.

3 Replies 3

Lei Tian
Cisco Employee
Cisco Employee

Hi Patrick,

What IP are you using for l2tpv3 tunnel?

HTH,
Lei Tian

Sent from Cisco Technical Support iPhone App

Lei,

That's a good question. I'll look tonight when I get home to look at my lab.

Thanks

paolo bevilacqua
Hall of Fame
Hall of Fame

Disable replay check altogether.

Review Cisco Networking products for a $25 gift card