cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
829
Views
6
Helpful
23
Replies

Spoke stuck on IKE state in DMVPN

INBK-IT
Level 1
Level 1

Hi,

We have mGRE DMVPN tunnle between one Hub and 7 Spokes. Other 6 Spokes are working fine but one Spoke is not connecting to Hub.

Spoke shows DMVPN on IKE state (tunnle is not working) and Hub is not adding nhrp entry in table.

INBKIT_0-1713981579965.png

Spoke DMVPN Tunnel

INBKIT_3-1713982713738.png

INBKIT_4-1713982931986.png

INBKIT_5-1713983001947.png

Please help.

 

23 Replies 23

you need to check matching
1- phaseI SA
2- PhaseII SA
3- Isakmp key 
MHM

INBK-IT
Level 1
Level 1

Hub:

INBKIT_0-1713984336309.png

Spoke:

INBKIT_1-1713984378145.png

When I do  Show crypto isakmp sa on Spoke it is empty same in Hub it dosen't show this Spoke5's entry.

 

Debug crypto isakmp

Show crypto isakmp sa

Share this

MHM

@MHM Cisco World 

This is what is see debug crypto isakmp

Hub:

INBKIT_0-1714053835347.png

INBKIT_2-1714058921835.png

 

Spoke:

INBKIT_1-1714053835338.png

INBKIT_3-1714059223929.png

 

Show crypto isakmp sa on Spoke it is empty same in Hub it dosen't show this Spoke5's entry.

 

Hmm, 
first use tunnel mode 
second config keepalive in both Hub and Spokes

MHM

@MHM Cisco World 

Tunnel mode is already set as gre multipoint on both side.

INBKIT_0-1714061416660.png

INBKIT_2-1714063694986.png

I searched and found out keepalives is not supported on DMVPN. Where and how do you want me to config keepalive on Hub and Spoke?

 

 

Keepalive of isamkp

And tunnel mode of crypto ipsec trans

MHM

@MHM Cisco World 

I inserted keepalive command for ISAKMP and now I see QM_IDLE state in both Hub & Spoke for each other when I do sh cryprto isakmp sa.

Also, I do see in Hub details when I do sh crypto ipsec sa in Spoke but when I do sh crypto ipsec sa in a Hub I do not see Spoke details.

Now, when I do sh dmvpn in Spoke it shows NHRP State all the time and in Hub dosen't show entry of this spoke. 

INBKIT_0-1714147561342.png

IPsec Transform-Sets are already sets in both Hub and Spoke from beginning.

Hub:

INBKIT_1-1714147774020.png

Spoke:

INBKIT_2-1714147817874.png

This meanly issue of NHRP register'

And try use 

Mode tunnel under crypto ipsec trans

You still use transport mode in hub.

Please share the config of ipsec all in spoke

Thanks 

MHM

 

@MHM Cisco World 

Yes you are right, there is an issue with NHRP Registration.

INBKIT_0-1714169150721.png

Don't want to change tunnel mode in Hub because other Spokes are connected and don't want mess with them.

Also, this Spoke was working with transport mode. 

it OK, in real you dont need to change the mode in Hub

you can change it in spoke only ( I am talking about mode tunnel)
for point it was work and now it not 
are the spoke WAN interface use DHCP or PPPoE to get IP ?

MHM

@MHM Cisco World 

As you recommended, I changed mode tunnel for Spoke.

INBKIT_1-1714341341726.png

This is what is see in Hub-sh log

INBKIT_0-1714341255249.png

And Spoke WAN Interface do not use DHCP or PPPoE to get IP.

 

This is what I see in Spoke's log:

INBKIT_0-1714343037962.png

 

I run Lab and the transport mode is not effect NHRP register 
so, retrun back use transport mode in Spoke 
share the 
show dmvpn detail <<- in spoke and Hub (for onyl this spoke)
and run 

debug nhrp packet <<- in spoke only 

share this 

MHM

Review Cisco Networking products for a $25 gift card