Guest

Preview Tool

Cisco Bug: CSCul52326 - L2TP/IPsec with NAT-T to ISR-G2 with ISM-VPN module fails

Last Modified

Nov 27, 2020

Products (74)

  • Cisco Software Activation on Integrated Services Routers
  • Cisco 888W Integrated Services Router
  • Cisco C897VA Integrated Services Router
  • Cisco 861W Integrated Services Router
  • Cisco 886VA-CUBE Integrated Services Router
  • Cisco 819 Hardened Integrated Services Router
  • Cisco 892W Integrated Services Router
  • Cisco 881SRSTW Integrated Services Router
  • Cisco C892FSP Integrated Services Router
  • Cisco 1905 Serial Integrated Services Router
View all products in Bug Search Tool Login Required

Known Affected Releases

15.3(3)M

Description (partial)

Symptom:
IKE Phase 1 and Phase 2 establishes, but we only see few packets decrypted (none encrypted). After couple of seconds both phases get cleared.
Traceback seen on ISM-VPN shim layer debug:
debug crypto engine ism shim

Conditions:
This symptom is observed under the following condition:
- ISR-G2 [1900/2900/3900] with active ISM-VPN module acting as L2TP over IPSec Server.
- L2TP PC is behind a NAT device, triggering NAT-traversal in IKE.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.