04-24-2024 11:29 AM
Hi,
We have mGRE DMVPN tunnle between one Hub and 7 Spokes. Other 6 Spokes are working fine but one Spoke is not connecting to Hub.
Spoke shows DMVPN on IKE state (tunnle is not working) and Hub is not adding nhrp entry in table.
Spoke DMVPN Tunnel
Please help.
04-24-2024 11:33 AM
you need to check matching
1- phaseI SA
2- PhaseII SA
3- Isakmp key
MHM
04-24-2024 11:52 AM
Hub:
Spoke:
When I do Show crypto isakmp sa on Spoke it is empty same in Hub it dosen't show this Spoke5's entry.
04-24-2024 02:01 PM
Debug crypto isakmp
Show crypto isakmp sa
Share this
MHM
04-25-2024 08:34 AM - edited 04-25-2024 08:37 AM
This is what is see debug crypto isakmp
Hub:
Spoke:
Show crypto isakmp sa on Spoke it is empty same in Hub it dosen't show this Spoke5's entry.
04-25-2024 08:38 AM
Hmm,
first use tunnel mode
second config keepalive in both Hub and Spokes
MHM
04-25-2024 09:53 AM
Tunnel mode is already set as gre multipoint on both side.
I searched and found out keepalives is not supported on DMVPN. Where and how do you want me to config keepalive on Hub and Spoke?
04-25-2024 09:58 AM
Keepalive of isamkp
And tunnel mode of crypto ipsec trans
MHM
04-26-2024 10:49 AM
I inserted keepalive command for ISAKMP and now I see QM_IDLE state in both Hub & Spoke for each other when I do sh cryprto isakmp sa.
Also, I do see in Hub details when I do sh crypto ipsec sa in Spoke but when I do sh crypto ipsec sa in a Hub I do not see Spoke details.
Now, when I do sh dmvpn in Spoke it shows NHRP State all the time and in Hub dosen't show entry of this spoke.
IPsec Transform-Sets are already sets in both Hub and Spoke from beginning.
Hub:
Spoke:
04-26-2024 10:55 AM
This meanly issue of NHRP register'
And try use
Mode tunnel under crypto ipsec trans
You still use transport mode in hub.
Please share the config of ipsec all in spoke
Thanks
MHM
04-26-2024 03:11 PM - edited 04-26-2024 03:11 PM
Yes you are right, there is an issue with NHRP Registration.
Don't want to change tunnel mode in Hub because other Spokes are connected and don't want mess with them.
Also, this Spoke was working with transport mode.
04-26-2024 03:17 PM
it OK, in real you dont need to change the mode in Hub
you can change it in spoke only ( I am talking about mode tunnel)
for point it was work and now it not
are the spoke WAN interface use DHCP or PPPoE to get IP ?
MHM
04-28-2024 02:58 PM
As you recommended, I changed mode tunnel for Spoke.
This is what is see in Hub-sh log
And Spoke WAN Interface do not use DHCP or PPPoE to get IP.
04-28-2024 03:24 PM
This is what I see in Spoke's log:
04-29-2024 12:22 AM
I run Lab and the transport mode is not effect NHRP register
so, retrun back use transport mode in Spoke
share the
show dmvpn detail <<- in spoke and Hub (for onyl this spoke)
and run
debug nhrp packet <<- in spoke only
share this
MHM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide