03/26/2020 7 People found this article helpful 456,843 Views
Troubleshooting and resolutions for the "IPSec packet from illegal host” message.
An “IPSec packet from illegal host” message can be due to a number of causes, including but not limited to any one of the following:
Additionally, try upgrading the firmware to the latest version. You may also want to delete both SAs and recreate them.
Fragmentation may still occur on the network under certain circumstances.For example, a host will set a bit flag in the IP header of all TCP frames it transmits which informs routers that fragmentation is not allowed. This is known as the “Don’t Fragment” or DF bit. When a router receives a frame that is too large to be transmitted onto the next network, it will check to see if the DF bit is set. If it is not, then the frame is fragmented and forwarded on to the destination. If the DF bit is set, then the router should discard the frame and return an ICMP message to the sender indicating that fragmentation was required but the DF bit was set. This process will fail if a router between the source and destination needs to fragment the frame and either fails to return the ICMP message to the sender, or the message gets blocked due to packet filtering. This is known as a “black hole router”. In this case, the frame will be discarded silently and the sender will retransmit the frame several times until the TCP session terminates.