Hi,

I have a vpn tunnel established between two cisco 831 boxes. Both
boxes are connected to the internet through an dsl/atm connection and
there's a linksys modem in place to convert from dsl/atm signaling to
ethernet in order to properly connect to the cisco router.

After some time without traffic (for example, at night) the ipsec
tunnel freezes with no understandable reason. First, the crytpo
hardware process consumes all the CPU (and the crypto tunnels stops
working correctly) and then, after some random time, the box freezes
completely.

The following show proc cpu was took before it freezes completely.

CPU utilization for five seconds: 99%/1%; one minute: 98%; five minutes: 98%
 PID Runtime(ms)   Invoked      uSecs   5Sec   1Min   5Min TTY Process
<snip>
  101     3804652     42158      90247 84.87% 90.91% 93.67%   0 Crypto
Hardware
<snip>

There is also hundreds of syslog messages (like the one below) when
the crypto hardware process freezes up.

Jun  3 16:10:14 BRT: %HIFN79XX-3-CMD_ERR: Hifn 79XX command returned
error: (0x1048)
Jun  3 16:10:14 BRT: chifn79xx_lopri_error: unknown error 0x1048
Jun  3 16:10:14 BRT: IPSECcard: an error coming back 0x1048, cmd = 53

Then, when I disable the hardware accelarator (no crypto engine
accelerator), all vpn tunnels start working again. The hardware crypto
engine starts working again only after a reload.

This behavior happen with 12.3(2)XE4 and 12.3(8)T11 IOS version. The
ipsec/vpn configuration is pretty simple, just 3des with md5 hash,
pre-shared keys and default timers (no PFS).

Have anybody saw something like this before?

Thanks,
Gustavo.
_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to