08-13-2013 06:30 AM - edited 03-04-2019 08:45 PM
Hi,
In dynamips I created a GRE tunnel over a VPN between 2 routers over a simulated Internet connection and it works great. I'm able to create EIGRP neighborships, exchange routes and ping across it all day without losing a ping.
Next, I created a l2TPv3 tunnel across the VPN to have a VLAN existing on both sides. Shortly after sending traffic across the l2TPv3 tunnel, the EIGRP neighborship fails, the tunnel breakes, and I start losing pings. The tunnel will then re-establish and the fail again and again and my pings will fail and succeed for a bit then fail.
Console message:
%CRYPTO-4-PKT_REPLAY_ERR replay check failed
From looking around for work-arounds I've increased the crypto ipsec security-association replay window-size to 1028 and used encryption only on both sides of the VPN but, still the tunnel breaks.
See attached diagram.
Any suggestions?
Thank you, Pat.
08-13-2013 04:19 PM
Hi Patrick,
What IP are you using for l2tpv3 tunnel?
HTH,
Lei Tian
Sent from Cisco Technical Support iPhone App
08-14-2013 08:50 AM
Lei,
That's a good question. I'll look tonight when I get home to look at my lab.
Thanks
08-14-2013 08:53 AM
Disable replay check altogether.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide