AR1200 IPsec Caused SIP Services Interrupt

Created Sep 29, 2018 10:32:00Latest reply Oct 01, 2018 19:30:35 1369 7 10 0

Issue Description :Customer configured two 100/Mbit IPsec Tunnels between AR1220E and Cisco ASR1002/ASR1004 , But after configured IPsec , Customer experienced packet loss , degraded network performance and SIP session Interrupted .

 

Handle Process :According to the configuration information on the device, only the AR and the peer ASR establish an IPsec tunnel. There is no NAT configuration. The SIP packets are encrypted and decrypted as IPsec packets.

 I don't see any IPsec flapping in the debug log. It can hear the ringing when the phone is talking. This indicates that there is SIP packet exchange. The IPsec tunnel is good. The existing information does not see any doubts.

 

Please follow below suggest get capture packets.

 1. For configured IPsec and without configured IPsec scenario, Please capture SIP packets on the AR connected to S57 to confirm the difference in SIP packet exchange.

 2. IPsec use the ah algorithm or does not use IPsec instead of  use the GRE tunnel. In this way, you can see the plain text packet. If the problem still exist, configure the IPsec or GRE interface on the AR and the S57 side interface to capture packets.

 

Capture one of the packets in the package:

 103644jkzub2bob4bb6o9o.jpg

 

Root Cause: According to the difference between the packet capture information and the test GRE over IPsec, the biggest possibility of the current analysis is that the fragmented packet is not allowed. After the IPsec

 encryption, the packet becomes larger, and fragmentation is not allowed, so the it is discarded by the intermediate network.

 

Solution :There are two commands to remove the fragmentation tag. It is recommended to configure the corresponding commands on both devices. You can configure it and test it:

1. Configure the clear ip df command on the interface to remove the not allow fragmentation tag when sending packets. Cisco did not find the corresponding command

2. Configure the IPsec df-bit clear command in the system view. IPsec does not copy the fragment tag from the IP header. After encryption, the packet is allowed to be fragmented. Cisco corresponds to the command

Router(config)#crypto IPsec

 df-bit clear

 

There are many packets in the packet that have tags do not allow fragmentation. Only when IPsec is encrypted, IPsec will copy the fragment tag in the IP header. After encryption, the fragmentation is not allowed. In the case of GRE over IPsec, the first GRE encapsulation does not determine the fragmentation bit in the Ip header, so fragmentation processing can be performed.

 

Suggest: If we can confirm the configuration is normal , suggest make debugging and capture packet.

 

This post was last edited by Skay at 2018-09-29 10:37.
  • x
  • convention:

No.9527  Mentor   Created Sep 29, 2018 13:53:04 Helpful(0) Helpful(0)

I am very interested for this post, which is very helpful to our daily troubleshooting. I always have similar problems in my daily work, but I do not know how to deal with them. Now I have a clear idea. Thank you very much for your sharing. Hope you can update continue like this
  • x
  • convention:

Mark.hu  Adept   Created Sep 29, 2018 14:04:27 Helpful(0) Helpful(0)

I have encountered this question about you. I have checked a lot of information, but I still have not answered this question clearly. Thank you for sharing this knowledge and solving my doubts. I hope that you can continue to update such knowledge points. Thank you. !
  • x
  • convention:

Torrent     Created Sep 29, 2018 14:09:08 Helpful(0) Helpful(0)

After reading this post verbatim, my heart can't be calm for a long time, shocking! Why are there such good posts? ! I have been on the Internet for many years, and I don’t think there will be any posts that will impress me. I didn’t expect to see such a wonderful post today.
The landlord, you let me deeply understand the phrase ‘there are people outside, there are days outside the sky’. Thank you!
After reading this post, I didn't respond immediately, because I was afraid that my vulgar response would tarnish this rare post on the Internet. But I still replied, because I feel that if I can't leave my own screen name behind such a wonderful post, then I will not be afraid of death! How proud it is to be able to leave your own screen name behind such a wonderful post! The landlord, please forgive my selfishness!
I know that no matter how gorgeous the rhetoric is used to describe the splendid degree of your post, it is not enough, it is hypocritical, so I just want to say: Your post is so good! I am willing to watch it all my life!
This post is novel in concept, with unique ingenuity, clear passages, different plots, ups and downs, distinct lines, fascinating and fascinating literary skills. It can be described as a word and a classic sentence, which is a model that my generation should learn.
I was already disappointed with this community. I feel that this community has no future, and my heart is full of sorrow. But after reading this post, I made hope for the community. It is you who let my heart rekindle the fire of hope. It is you who have revived my heart. You saved me a cool and cool heart!
Originally, I decided not to return any posts in the community, but after reading your post, I told myself that this post must be returned! This is a rare sticker that has been rare for a hundred years! Heaven has eyes, let me see such a wonderful post in the eugenic year.
  • x
  • convention:

SupperRobin  Novice   Created Sep 29, 2018 14:39:50 Helpful(0) Helpful(0)

This section describes how to configure parameters of a SIP server, including the IP address, URI, and home domain. SIP server is an important entity in the SIP protocol architecture. The PBX can function as the SIP server to accept registration information of SIP users, save the information in the address information database, and manage and maintain users' registration information. This post was last edited by SupperRobin at 2018-10-31 15:07.
  • x
  • convention:

yangyong  Adept   Created Sep 30, 2018 21:45:03 Helpful(0) Helpful(0)

This post is novel in concept, with unique ingenuity, clear passages, different plots, ups and downs, distinct lines, fascinating and fascinating literary skills. It can be described as a word and a classic sentence, which is a model that my generation should learn. I am very interested for this post, which is very helpful to our daily troubleshooting.
  • x
  • convention:

faysalji  Novice   Created Oct 01, 2018 19:30:12 Helpful(0) Helpful(0)

Thanks for sharing
  • x
  • convention:

If you think my post/reply is useful, please click the Helpful button and flag my post as a BEST ANSWER. Thanks
faysalji  Novice   Created Oct 01, 2018 19:30:35 Helpful(0) Helpful(0)

Posted by Torrent at 2018-09-29 11:09 After reading this post verbatim, my heart can't be calm for a long time, shocking! Why are there su ...
  • x
  • convention:

If you think my post/reply is useful, please click the Helpful button and flag my post as a BEST ANSWER. Thanks

Responses

Reply
You need to log in to reply to the post Login | Register

Notice:To ensure the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but not limited to politically sensitive content, content concerning pornography, gambling, drug abuse and trafficking, content that may disclose or infringe upon others' intellectual properties, including commercial secrets, trade marks, copyrights, and patents, and personal privacy. Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see“ Privacy Policy.”
If the attachment button is not available, update the Adobe Flash Player to the latest version!
Fast reply Scroll to top