Guest

Preview Tool

Cisco Bug: CSCuj47795 - Anti-replay protection disabled when using IKEv2 and AES-GMC or AES-GMAC

Last Modified

Aug 06, 2018

Products (74)

  • Cisco IOS
  • Cisco 892W Integrated Services Router
  • Cisco 886VA-CUBE Integrated Services Router
  • Cisco 2951 Integrated Services Router
  • Cisco 888W Integrated Services Router
  • Cisco 861W Integrated Services Router
  • Cisco 886VAG 3G Integrated Services Router
  • Cisco 1905 Serial Integrated Services Router
  • Cisco 812 CiFi Integrated Services Router
  • Cisco C897VA Integrated Services Router
View all products in Bug Search Tool Login Required

Known Affected Releases

15.3(3)M

Description (partial)

Symptom:
Anti-replay protection is disabled for Phase II IPSec SAs. A ''show crypto ipsec sa'' will show ''replay detection support: N''. Example:

Router#sh crypto ipsec sa  | i trans|repl
        transform: esp-gcm 256 ,
        replay detection support: N
        transform: esp-gcm 256 ,
Router#

Conditions:
IKEv2 is being used for negotiating Phase I SAs, and the Phase II transform set is configured to use either AES-GCM or AES-GMAC with any number 
(128, 192 or 256) of bits.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.