Got it

AR1200 IPsec Caused SIP Services Interrupt

Latest reply: Oct 1, 2018 11:30:35 1859 7 10 0 0

Hello everyone,

Today I will introduce to you the SIP service interruption caused by AR1200 IPsec。

Issue Description

Customer configured two 100/Mbit IPsec Tunnels between AR1220E and Cisco ASR1002/ASR1004, But after configured IPsec, Customer experienced packet loss, degraded network performance and SIP session Interrupted.

 

Handle Process

According to the configuration information on the device, only the AR and the peer ASR establish an IPsec tunnel. There is no NAT configuration. The SIP packets are encrypted and decrypted as IPsec packets. I don't see any IPsec flapping in the debug log. It can hear the ringing when the phone is talking. This indicates that there is SIP packet exchange. The IPsec tunnel is good. The existing information does not see any doubts.

Please follow below suggest getting capture packets.

1. For configured IPsec and without configured IPsec scenario, Please capture SIP packets on the AR connected to S57 to confirm the difference in SIP packet exchange.

2. IPsec use the ah algorithm or does not use IPsec instead of using the GRE tunnel. In this way, you can see the plain text packet. If the problem still exist, configure the IPsec or GRE interface on the AR and the S57 side interface to capture packets.

 

Capture one of the packets in the package:

 103644jkzub2bob4bb6o9o.jpg

 

Root Cause

According to the difference between the packet capture information and the test GRE over IPsec, the biggest possibility of the current analysis is that the fragmented packet is not allowed. After the IPsec encryption, the packet becomes larger, and fragmentation is not allowed, so it is discarded by the intermediate network.

 

Solution

There are two commands to remove the fragmentation tag. It is recommended to configure the corresponding commands on both devices. You can configure it and test it:

1. Configure the clear ip df command on the interface to remove the not allow fragmentation tag when sending packets. Cisco did not find the corresponding command

2. Configure the IPsec df-bit clear command in the system view. IPsec does not copy the fragment tag from the IP header. After encryption, the packet is allowed to be fragmented. Cisco corresponds to the command

Router(config)#crypto IPsec

 df-bit clear

There are many packets in the packet that has tags do not allow fragmentation. Only when IPsec is encrypted, IPsec will copy the fragment tag in the IP header. After encryption, fragmentation is not allowed. In the case of GRE over IPsec, the first GRE encapsulation does not determine the fragmentation bit in the Ip header, so fragmentation processing can be performed.


Suggest

If we can confirm the configuration is normal, suggest make debugging and capture packets.

That is all I want to share with you! Thank you!

 

  • x
  • convention:

No.9527
Created Sep 29, 2018 05:53:04

I am very interested for this post, which is very helpful to our daily troubleshooting. I always have similar problems in my daily work, but I do not know how to deal with them. Now I have a clear idea. Thank you very much for your sharing. Hope you can update continue like this
View more
  • x
  • convention:

Mark.hu
Created Sep 29, 2018 06:04:27

I have encountered this question about you. I have checked a lot of information, but I still have not answered this question clearly. Thank you for sharing this knowledge and solving my doubts. I hope that you can continue to update such knowledge points. Thank you. !AR1200 IPsec Caused SIP Services Interrupt-2765125-1AR1200 IPsec Caused SIP Services Interrupt-2765125-2
View more
  • x
  • convention:

Torrent
Created Sep 29, 2018 06:09:08

After reading this post verbatim, my heart can't be calm for a long time, shocking! Why are there such good posts? ! I have been on the Internet for many years, and I don’t think there will be any posts that will impress me. I didn’t expect to see such a wonderful post today.
The landlord, you let me deeply understand the phrase ‘there are people outside, there are days outside the sky’. Thank you!
After reading this post, I didn't respond immediately, because I was afraid that my vulgar response would tarnish this rare post on the Internet. But I still replied, because I feel that if I can't leave my own screen name behind such a wonderful post, then I will not be afraid of death! How proud it is to be able to leave your own screen name behind such a wonderful post! The landlord, please forgive my selfishness!
I know that no matter how gorgeous the rhetoric is used to describe the splendid degree of your post, it is not enough, it is hypocritical, so I just want to say: Your post is so good! I am willing to watch it all my life!
This post is novel in concept, with unique ingenuity, clear passages, different plots, ups and downs, distinct lines, fascinating and fascinating literary skills. It can be described as a word and a classic sentence, which is a model that my generation should learn.
I was already disappointed with this community. I feel that this community has no future, and my heart is full of sorrow. But after reading this post, I made hope for the community. It is you who let my heart rekindle the fire of hope. It is you who have revived my heart. You saved me a cool and cool heart!
Originally, I decided not to return any posts in the community, but after reading your post, I told myself that this post must be returned! This is a rare sticker that has been rare for a hundred years! Heaven has eyes, let me see such a wonderful post in the eugenic year.
View more
  • x
  • convention:

SupperRobin
Created Sep 29, 2018 06:39:50

This section describes how to configure parameters of a SIP server, including the IP address, URI, and home domain. SIP server is an important entity in the SIP protocol architecture. The PBX can function as the SIP server to accept registration information of SIP users, save the information in the address information database, and manage and maintain users' registration information. This post was last edited by SupperRobin at 2018-10-31 07:07.
View more
  • x
  • convention:

yangyong
Created Sep 30, 2018 13:45:03

This post is novel in concept, with unique ingenuity, clear passages, different plots, ups and downs, distinct lines, fascinating and fascinating literary skills. It can be described as a word and a classic sentence, which is a model that my generation should learn. I am very interested for this post, which is very helpful to our daily troubleshooting.
View more
  • x
  • convention:

faysalji
Author Created Oct 1, 2018 11:30:12

Thanks for sharing
View more
  • x
  • convention:

faysalji
Author Created Oct 1, 2018 11:30:35

Posted by Torrent at 2018-09-29 03:09 After reading this post verbatim, my heart can't be calm for a long time, shocking! Why are there su ...
AR1200 IPsec Caused SIP Services Interrupt-2767675-1
View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.