Hi, I have a vpn tunnel established between two cisco 831 boxes. Both boxes are connected to the internet through an dsl/atm connection and there's a linksys modem in place to convert from dsl/atm signaling to ethernet in order to properly connect to the cisco router.
After some time without traffic (for example, at night) the ipsec tunnel freezes with no understandable reason. First, the crytpo hardware process consumes all the CPU (and the crypto tunnels stops working correctly) and then, after some random time, the box freezes completely. The following show proc cpu was took before it freezes completely. CPU utilization for five seconds: 99%/1%; one minute: 98%; five minutes: 98% PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process <snip> 101 3804652 42158 90247 84.87% 90.91% 93.67% 0 Crypto Hardware <snip> There is also hundreds of syslog messages (like the one below) when the crypto hardware process freezes up. Jun 3 16:10:14 BRT: %HIFN79XX-3-CMD_ERR: Hifn 79XX command returned error: (0x1048) Jun 3 16:10:14 BRT: chifn79xx_lopri_error: unknown error 0x1048 Jun 3 16:10:14 BRT: IPSECcard: an error coming back 0x1048, cmd = 53 Then, when I disable the hardware accelarator (no crypto engine accelerator), all vpn tunnels start working again. The hardware crypto engine starts working again only after a reload. This behavior happen with 12.3(2)XE4 and 12.3(8)T11 IOS version. The ipsec/vpn configuration is pretty simple, just 3des with md5 hash, pre-shared keys and default timers (no PFS). Have anybody saw something like this before? Thanks, Gustavo. _______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
