Results 1 to 5 of 5

Thread: ASA failed anti-replay checking

  1. #1
    ipsec is offline Member
    Join Date
    Jul 2009
    Posts
    63

    Default ASA failed anti-replay checking

    What does this error mean?

    :%ASA-vpn-4-402119: IPSEC: Received an ESP packet (SPI= 0xBF529470, sequence number= 0xB96D) from 175.232.23.16 (user= user1) to 209.175.12.24 that failed anti-replay checking.

  2. #2
    foxbot is offline Senior Member
    Join Date
    Jul 2009
    Posts
    140

    Default

    This message is displayed when an IPsec packet is received with an invalid sequence number. This is more than likely due to the peer sending packets containing sequence number that may have been previously used or sending them out of order due to packet loss on the client’s end. You can increase the anti-reply window with the command: crypto IPsec security-association replay window-size 1024. This command should help with clients with poor internet connections.

  3. #3
    ipsec is offline Member
    Join Date
    Jul 2009
    Posts
    63

    Default

    Thanks. I will try this command and will see if it stops this error.

  4. #4
    vijaytransformers is offline Junior Member
    Join Date
    Apr 2012
    Posts
    12

  5. #5
    vijaytransformers is offline Junior Member
    Join Date
    Apr 2012
    Posts
    12

Similar Threads

  1. Hotel Guests Checking Into Public Cisco TelePresence Rooms
    By robocisco in forum Cisco News Discussion
    Replies: 0
    Last Post: 01-27-2010, 05:01 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •