# Packet drops in the IPsec Tunnel between Cisco ASA firewalls

**URL:** https://forum.networklessons.com/t/packet-drops-in-the-ipsec-tunnel-between-cisco-asa-firewalls/15615
**Category:** ASA
**Created:** [October 19, 2021, 5:14pm UTC](https://forum.networklessons.com/t/packet-drops-in-the-ipsec-tunnel-between-cisco-asa-firewalls/15615 "2021-10-19T17:14:38Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![shivani.bsc29](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/s/b487fb/32.png) [@shivani.bsc29](https://forum.networklessons.com/u/shivani.bsc29)
#### Post date: [October 19, 2021, 5:14pm UTC](https://forum.networklessons.com/t/packet-drops-in-the-ipsec-tunnel-between-cisco-asa-firewalls/15615/1 "2021-10-19T17:14:38Z")

</div>

Hi ,  
I am facing connectivity issue through the IPsec tunnel configured between Cisco ASA firewalls. Pls help & suggest the way forward to troubleshoot it.

Scenario: The IPsec tunnel (Ikev1) was stable since years but suddenly started observing random packet drops between the interesting traffic only. There are no packet drops to the remote peer public IP address at the same time ?

---

<div class="post-metadata">

### Author: ![lagapidis](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/lagapidis/32/4949_2.png) [@lagapidis](https://forum.networklessons.com/u/lagapidis)
#### Post date: [October 21, 2021, 6:28am UTC](https://forum.networklessons.com/t/packet-drops-in-the-ipsec-tunnel-between-cisco-asa-firewalls/15615/2 "2021-10-21T06:28:16Z")

</div>

Hello Shivani

There may be several reasons for such an occurrence. In order to help you with troubleshooting, take a look at the following post:

> [@Cisco ASA Site-to-Site IKEv1 IPsec VPN](https://forum.networklessons.com/t/cisco-asa-site-to-site-ikev1-ipsec-vpn/825/101):
>
> Hello Pavan Recieve errors on an IKEv1 IPSec tunnel usually increase when one of the tests performed during the decapsulation of the ESP fails. These include: Anti-replay out of window errors Digest errors (packet corrupted) Invalid decapsulation length/SA/protocol Any other decapsulation failure In order to determine in detail where the problem is, you can use various debug commands for IPSec including: debug crypto ipsec debug crypto isakmp If it is an issue with ESP decapsulation, you …

You may also find some additional help at this NetworkLessons note:

[https://notes.networklessons.com/asa-troubleshooting-ipsec](https://notes.networklessons.com/asa-troubleshooting-ipsec)

Let us know how you get along in your troubleshooting!

I hope this has been helpful!

Laz
