[c-nsp] debug IPSEC explanation

Bruce Pinsky bep at whack.org
Tue Mar 15 19:22:14 EST 2005


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Luan Nguyen wrote:
| Hi All,
|
|
|
| Does anyone know what the following debugs mean by any chance?  Running IOS
| 12.3.11T3 on a 1711
|
|
|
| "004347: Mar 15 03:19:28.151 GMT: IPSEC(crypto_map_check_encrypt_core):
| mtree says we have SA but couldn't find current outbound SA. dropping pak.
| pak->cryptoflags=0x820"
|
|


This apparently occurs as a result of a transient condition where a
structure that tracks SAs believes one exists but the structure that holds
the SAs no longer has it.

- --
=========
bep

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.0 (MingW32)

iD8DBQFCN3w2E1XcgMgrtyYRAtNGAJ4soZqIIeiNh7k1vghPpry41MLsxgCgm36q
4ohk7gcVRtgG0q26dezQuXE=
=V4hI
-----END PGP SIGNATURE-----


More information about the cisco-nsp mailing list