A branch router shows 'encap pkts' increasing in 'show crypto ipsec sa' but 'decap pkts' remains zero on the peer. Which single troubleshooting conclusion is most plausible?
Choose an answer
Tap an option to check your answer.
Correct answer: The peer is receiving encrypted packets but cannot decrypt them due to mismatched IPsec transforms or keys.
Why this is the answer
When 'encap pkts' increases on one router but 'decap pkts' remains zero on the peer, it indicates that the first router is successfully encrypting and sending traffic, but the peer is not successfully decrypting it. This is a classic symptom of a mismatch in IPsec parameters such as transform sets, pre-shared keys, or other Phase 2 (IPsec SA) configurations. The peer receives the encrypted packets but cannot establish a valid Security Association to decrypt them. Incorrect options: "The route to the peer is incorrect because there are no encapsulated packets" is wrong because 'encap pkts' are increasing, meaning packets are being encapsulated and sent. "The encapsulated packets are being fragmented and dropped only on the local router" is wrong because if packets were dropped locally, 'encap pkts' might not increase, or the issue would be before transmission. The packets are clearly reaching the peer. "The local router has no crypto ACL so it is not selecting traffic to encrypt" is wrong because 'encap pkts' are increasing, which confirms that the local router is selecting and encrypting traffic.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed