IPSec stop working after time X on CCR1072

Hello,

I have a Problem on 2 CCR1072 with VRRP.
IPSec stop working after time X ( 1 day, 2 day, a half day, etc. )
No traffic was send. I have delect all Connections and flush SAs but it don’t help. Only a restart work.
On the other end is also a Microtik RB3011UiAS-RM
I have change the Level in IPSec to unique, but that don’t Change anything.

OS Version is 6.39.1

KR
Oliver

Hello,

there is High CPU (45%) usage, when the IPSec don’t send traffic.

Networking 41 %
unclassified 5 %
total 46,9 %

KR
Oliver

Hello Olivier,

I’ve got same issues with CCR1072-1G-8S+
After 1, 2 or 8 days and without any High CPU situation, all IPsec fall and only Routerboard reboot solves situation.

Any ideas or help will be highly appreciated!

Matthieu

I’m really problem

I also have CCR1072 + ipsec + vrrp, locking ipsec in this same range clock

I tested versions 6.39.3, 6.37.5, but i’m currently in the version 6.38.7

Currently I have 73 (IPIP + ipsec tunnels), 14 (tunnels EOIP + ipsec) and some vpns L2TP with ipsec. But next year I intend to add 100 more tunnels, all 5Mbs

I disabled all vrrp interfaces, left only the IPs over vlan and bridge and I am monitoring.

Unfortunately CCR1072 came to lock all tunnels ipsec on “ipip, eoip and l2tp” even after disabled vrrp interfaces.

I saw version 6.39 brought hardware acceleration ipsec, I upgraded …

Please generate supout.rif file when the issue is present on the router and send it to support@mikrotik.com.