Configure IPsec Tunnel Parameters - replay-window

Information

By default, the IPsec replay window on the IPsec tunnel is 512 bytes.

See https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/security/vedge-20-x/security-book/config-sec-param.html for more information.

Solution

You can set the replay window size to 64, 128, 256, 512, 1024, 2048, or 4096 packets:

vEdge(config-interface-ipsecnumber)# ipsec
vEdge(config-ipsec)# replay-window number

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-4

Plugin: Cisco_Viptela

Control ID: 15d801bacd0bf01e2f2efa0c7bd67c37f17d31a0aeb04db62be18823aa9eb1b8