Bug #8961
closedIPSEC issues with Asynchronous Cryptography
Start date:
Due date:
% Done:
Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
Affected Architecture:
With the release of 2.4.4 we enabled `Asynchronous Cryptography` by default, we are seeing cases where traffic does not pass over the ipsec tunnel with this enabled.
ICMP to a known host on the tunnel works, when trying to connect by UDP or TCP to the same host, traffic is not passing.
PCAPS show the SYN on the IPSEC interface, but no correlating ESP traffic leaving the device.
We have had reports of disabling async on one side of the tunnel does not resolve the issue, both sides need to be disabled for traffic to work again.
Updated by Anonymous about 6 years ago
- Target version changed from 2.4.4-GS to 2.4.4-p1
Updated by Jim Pingle about 6 years ago
- Status changed from New to Duplicate
Duplicate of #8964 (it came later, but has more detail and comments with additional info)