Users are experiencing packet loss with ISAKMP packets when passing through Cisco IOL routers. A feature to prevent this issue would enhance reliability in VPN setups.
I have a VPN tunnel between two firewalls in my lab. Somehow, ISAKMP packets are getting lost as soon as they pas through a Cisco IOL router. They're not all getting dropped, just like 2/3 of them. The ISAKMP packets are fragmented at the iSAKMP level; the IP and UDP headers should appear as normal. The packet sizes are not high; less than 1200 bytes (on a standard 1500 MTU network). I cannot figure out if there is some default Cisco IOS behavior that would cause ISAKMP packets (that aren't even destined for the IOL's control plane) to get dropped in transit, or if this is just yet another IOL bug. NOTE: The router's configuration is as basic as can be. Just basic IP connectivity and some light BGP. Nothing beyond that. I have also tried disabling CEF and it made no difference. I do not have this issue with Layer 2 IOL Switches. EDIT: I just tested this with a CSR router instead... it's not dropping the packets. So, perhaps an IOL fluke?