Actions
Bug #8961
closedIPSEC issues with Asynchronous Cryptography
Start date:
09/26/2018
Due date:
% Done:
0%
Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
Affected Architecture:
Description
With the release of 2.4.4 we enabled `Asynchronous Cryptography` by default, we are seeing cases where traffic does not pass over the ipsec tunnel with this enabled.
ICMP to a known host on the tunnel works, when trying to connect by UDP or TCP to the same host, traffic is not passing.
PCAPS show the SYN on the IPSEC interface, but no correlating ESP traffic leaving the device.
We have had reports of disabling async on one side of the tunnel does not resolve the issue, both sides need to be disabled for traffic to work again.
Actions