This message is displayed when an IPsec packet is received with an invalid sequence number. This is more than likely due to the peer sending packets containing sequence number that may have been previously used or sending them out of order due to packet loss on the client’s end. You can increase the anti-reply window with the command: crypto IPsec security-association replay window-size 1024. This command should help with clients with poor internet connections.



LinkBack URL
About LinkBacks



Reply With Quote
Bookmarks