Link to home
Start Free TrialLog in
Avatar of leblanc
leblanc

asked on

errors on site-to-site vpn

I have 4 site-to-site vpn with Cisco routers without ASA firewall. When I did the show crypto ipsec sa, I see send errors and recv errors. What are those errors? Can I see the meaning of those errors somewhere? Thanks
ASKER CERTIFIED SOLUTION
Avatar of John
John
Flag of Canada image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of leblanc
leblanc

ASKER

Sure. Everything is working fine. I am just trying to validate those errors. I want to be able to tell my boss what types of errors it is, even though it is not affecting the VPN traffic. Thanks
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of leblanc

ASKER

So there is no way to see the meaning of those errors, unless I monitor the connection or do some debug. Correct?
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of leblanc

ASKER

Got it. Thanks
Avatar of Rafael
Yes that is correct.  As John indicated you'll go nuts trying to decipher the messages.

-Rafael
So I think you have all you need and you did not post any specific errors. So if that is all, please do not forget to close out the question.  Thank you.
@bobon - Thanks much. And despite what was said above, it is worth your while, in a spare moment, to look through packets just to see what is there.
Avatar of leblanc

ASKER

Yes. I will have to be on site to setup Wireshark for the monitoring. IT is too bad you can see the errors but we don't know what it is until we look into the packets. I don't have a lot of experience with VPN. So if I look at those errors numbers, I will assume that something is wrong with the connection. But like you mentioned it may just be retransmissions.