Guest

Preview Tool

Cisco Bug: CSCuo86128 - ASR1k stops encapulating IPSEC traffic hours after upgrade

Last Modified

Jun 16, 2014

Products (1)

  • Cisco ASR 1000 Series Aggregation Services Routers

Known Affected Releases

15.3TPI19

Description (partial)

Not enough info. May not be a software bug.Symptom:An hour after upgrading software on ASR1k may stop encapsulating ipv4 traffic into Ipsec tunnels. But, de-encapsulation of ipv4 traffic works normally.

# show crypto ipsec sa
    #pkts encaps: 0, #pkts encrypt: 0, #pkts digest: 0  <<<<<<!!!!!
    #pkts decaps: 5, #pkts decrypt: 5, #pkts verify: 5


Conditions:ASR1k was upgrade from asr1000rp2-advipservicesk9.03.02.01.S.151-1.S1 to asr1000rp2-adventerprisek9.03.08.02.S.153-1.S2 an hour before it happened.  Fifty other ASR1ks were upgraded with the identical process without an issue.  Lab recreates by the BU and TAC were unsuccessful.  Root cause remains unknown.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.