cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
971
Views
6
Helpful
23
Replies

Spoke stuck on IKE state in DMVPN

INBK-IT
Level 1
Level 1

Hi,

We have mGRE DMVPN tunnle between one Hub and 7 Spokes. Other 6 Spokes are working fine but one Spoke is not connecting to Hub.

Spoke shows DMVPN on IKE state (tunnle is not working) and Hub is not adding nhrp entry in table.

INBKIT_0-1713981579965.png

Spoke DMVPN Tunnel

INBKIT_3-1713982713738.png

INBKIT_4-1713982931986.png

INBKIT_5-1713983001947.png

Please help.

 

23 Replies 23

@MHM Cisco World 

Show DMVPN Detail

Spoke:

INBKIT_1-1714402122687.png

Hub dosen't have entry of this Spoke when I do Show DMVPN Detail

Please see output of debug nhrp packet in Spoke

INBKIT_3-1714403382723.png

 

MHM

 

when you config keepalive did you add it to both Hub and spoke ?

can you share the exact command you use ?

MHM

@MHM Cisco World 

I added #crypto isakmp keepalive 10 in both Hub and Spoke.

 

that Correct 
can you 
shut the interface in spoke 
run debug dmvpn detail all in both Hub and Spoke 

Note:- in hub use "" debug dmvpn condition peer x.x.x.x"" this tune debug to only spoke we have problem with

no shut the interface in spoke 
check 

@MHM Cisco World 

Both Spoke and Hub's log after shut/no shut the tunnel. 

Spoke's Log:

*May 1 17:03:26.239: prefix: 32, mtu: 9972, hd_time: 7200
*May 1 17:03:26.239: addr_len: 0(NSAP), subaddr_len: 0(NSAP), proto_len: 0, pref: 255
*May 1 17:03:26.239: Responder Address Extension(3):
*May 1 17:03:26.239: Forward Transit NHS Record Extension(4):
*May 1 17:03:26.239: Reverse Transit NHS Record Extension(5):
*May 1 17:03:26.239: Authentication Extension(7):
*May 1 17:03:26.239: type:Cleartext(1), data:IBCVPN
*May 1 17:03:26.239: NAT address Extension(9):
*May 1 17:03:26.239: (C-1) code: no error(0)
*May 1 17:03:26.239: prefix: 32, mtu: 9972, hd_time: 0
*May 1 17:03:26.239: addr_len: 4(NSAP), subaddr_len: 0(NSAP), proto_len: 4, pref: 255
*May 1 17:03:26.239: client NBMA: Hub's Public IP
*May 1 17:03:26.239: client protocol: 172.168.1.3
*May 1 17:03:26.239: NHRP-DETAIL: Unable to get dst from pak sb
*May 1 17:03:26.239: NHRP-CACHE: Setting 'used' flag on cache entry with nhop: 172.168.1.3
*May 1 17:03:26.239: NHRP: Encapsulation succeeded. Sending NHRP Control Packet NBMA Address: Hub's Public IP
*May 1 17:03:26.239: NHRP: 134 bytes out Tunnel0
*May 1 17:03:26.239: NHRP: Resetting retransmit due to hold-timer for 172.168.1.3
*May 1 17:03:26.239: IPSEC-IFC MGRE/Tu0: tunnel coming up
*May 1 17:03:26.240: IPSEC-IFC MGRE/Tu0: crypto_ss_listen_start already listening
*May 1 17:03:26.240: IPSEC-IFC MGRE/Tu0: crypto_ss_listen_start already listening
*May 1 17:03:26.240: IPSEC-IFC MGRE/Tu0(Spoke's Public IP/Hub's Public IP): Opening a socket with profile IBC_PROFILE
*May 1 17:03:26.240: IPSEC-IFC MGRE/Tu0(Spoke's Public IP/Hub's Public IP): connection lookup returned 7F6263416268
*May 1 17:03:26.240: IPSEC-IFC MGRE/Tu0(Spoke's Public IP/Hub's Public IP): Found an existing tunnel endpoint
*May 1 17:03:26.240: IPSEC-IFC MGRE/Tu0(Spoke's Public IP/Hub's Public IP): Socket is already open. Ignoring.
*May 1 17:03:27.237: %LINEPROTO-5-UPDOWN: Line protocol on Interface Tunnel0, changed state to up
*May 1 17:03:27.966: NHRP: Setting retrans delay to 4 for nhs dst 172.168.1.3
*May 1 17:03:27.966: IPSEC-IFC MGRE/Tu0(Spoke's Public IP/Hub's Public IP): connection lookup returned 7F6263416268
*May 1 17:03:27.966: NHRP: Attempting to send packet through interface Tunnel0 via DEST dst 172.168.1.3
*May 1 17:03:27.966: NHRP: Send Registration Request via Tunnel0 vrf global(0x0), packet size: 106
*May 1 17:03:27.966: src: 172.168.1.5, dst: 172.168.1.3
*May 1 17:03:27.966: (F) afn: AF_IP(1), type: IP(800), hop: 255, ver: 1
*May 1 17:03:27.966: shtl: 4(NSAP), sstl: 0(NSAP)
*May 1 17:03:27.966: pktsz: 106 extoff: 52
*May 1 17:03:27.966: (M) flags: "unique nat ", reqid: 297
*May 1 17:03:27.966: src NBMA: Spoke's Public IP
*May 1 17:03:27.966: src protocol: 172.168.1.5, dst protocol: 172.168.1.3
*May 1 17:03:27.966: (C-1) code: no error(0)
*May 1 17:03:27.966: prefix: 32, mtu: 9972, hd_time: 7200
*May 1 17:03:27.966: addr_len: 0(NSAP), subaddr_len: 0(NSAP), proto_len: 0, pref: 255
*May 1 17:03:27.966: Responder Address Extension(3):
*May 1 17:03:27.966: Forward Transit NHS Record Extension(4):
*May 1 17:03:27.966: Reverse Transit NHS Record Extension(5):
*May 1 17:03:27.966: Authentication Extension(7):
*May 1 17:03:27.966: type:Cleartext(1), data:IBCVPN
*May 1 17:03:27.966: NAT address Extension(9):
*May 1 17:03:27.966: (C-1) code: no error(0)
*May 1 17:03:27.966: prefix: 32, mtu: 9972, hd_time: 0
*May 1 17:03:27.966: addr_len: 4(NSAP), subaddr_len: 0(NSAP), proto_len: 4, pref: 255
*May 1 17:03:27.966: client NBMA: Hub's Public IP
*May 1 17:03:27.966: client protocol: 172.168.1.3
*May 1 17:03:27.966: NHRP-DETAIL: Unable to get dst from pak sb
*May 1 17:03:27.966: NHRP: Encapsulation succeeded. Sending NHRP Control Packet NBMA Address: Hub's Public IP
*May 1 17:03:27.966: NHRP: 134 bytes out Tunnel0
*May 1 17:03:27.966: NHRP-RATE: Retransmitting Registration Request for 172.168.1.3, reqid 297, (retrans ivl 4 sec)
*May 1 17:03:31.345: NHRP: NHS-DOWN: 172.168.1.3
*May 1 17:03:31.345: NHRP: Already pending Registration Request for NHS: 172.168.1.3
*May 1 17:03:31.345: NHRP: NHS 172.168.1.3 Tunnel0 vrf 0 Cluster 0 Priority 0 Transitioned to 'E' from 'E'

*May 1 17:03:31.345: NHRP: Setting retrans delay to 8 for nhs dst 172.168.1.3
*May 1 17:03:31.345: IPSEC-IFC MGRE/Tu0(Spoke's Public IP/Hub's Public IP): connection lookup returned 7F6263416268
*May 1 17:03:31.345: NHRP: Attempting to send packet through interface Tunnel0 via DEST dst 172.168.1.3
*May 1 17:03:31.345: NHRP: Send Registration Request via Tunnel0 vrf global(0x0), packet size: 106
*May 1 17:03:31.345: src: 172.168.1.5, dst: 172.168.1.3
*May 1 17:03:31.345: (F) afn: AF_IP(1), type: IP(800), hop: 255, ver: 1
*May 1 17:03:31.345: shtl: 4(NSAP), sstl: 0(NSAP)
*May 1 17:03:31.345: pktsz: 106 extoff: 52
*May 1 17:03:31.345: (M) flags: "unique nat ", reqid: 297
*May 1 17:03:31.345: src NBMA: Spoke's Public IP
*May 1 17:03:31.345: src protocol: 172.168.1.5, dst protocol: 172.168.1.3
*May 1 17:03:31.345: (C-1) code: no error(0)
*May 1 17:03:31.345: prefix: 32, mtu: 9972, hd_time: 7200
*May 1 17:03:31.345: addr_len: 0(NSAP), subaddr_len: 0(NSAP), proto_len: 0, pref: 255
*May 1 17:03:31.345: Responder Address Extension(3):
*May 1 17:03:31.345: Forward Transit NHS Record Extension(4):
*May 1 17:03:31.345: Reverse Transit NHS Record Extension(5):
*May 1 17:03:31.345: Authentication Extension(7):
*May 1 17:03:31.345: type:Cleartext(1), data:IBCVPN
*May 1 17:03:31.345: NAT address Extension(9):
*May 1 17:03:31.346: (C-1) code: no error(0)
*May 1 17:03:31.346: prefix: 32, mtu: 9972, hd_time: 0
*May 1 17:03:31.346: addr_len: 4(NSAP), subaddr_len: 0(NSAP), proto_len: 4, pref: 255
*May 1 17:03:31.346: client NBMA: Hub's Public IP
*May 1 17:03:31.346: client protocol: 172.168.1.3
*May 1 17:03:31.346: NHRP-DETAIL: Unable to get dst from pak sb
*May 1 17:03:31.346: NHRP: Encapsulation succeeded. Sending NHRP Control Packet NBMA Address: Hub's Public IP
*May 1 17:03:31.346: NHRP: 134 bytes out Tunnel0
*May 1 17:03:31.346: NHRP-RATE: Retransmitting Registration Request for 172.168.1.3, reqid 297, (retrans ivl 8 sec)
*May 1 17:03:38.065: NHRP: Setting retrans delay to 16 for nhs dst 172.168.1.3
*May 1 17:03:38.065: IPSEC-IFC MGRE/Tu0(Spoke's Public IP/Hub's Public IP): connection lookup returned 7F6263416268
*May 1 17:03:38.065: NHRP: Attempting to send packet through interface Tunnel0 via DEST dst 172.168.1.3
*May 1 17:03:38.065: NHRP: Send Registration Request via Tunnel0 vrf global(0x0), packet size: 106
*May 1 17:03:38.065: src: 172.168.1.5, dst: 172.168.1.3
*May 1 17:03:38.065: (F) afn: AF_IP(1), type: IP(800), hop: 255, ver: 1
*May 1 17:03:38.065: shtl: 4(NSAP), sstl: 0(NSAP)
*May 1 17:03:38.065: pktsz: 106 extoff: 52
*May 1 17:03:38.065: (M) flags: "unique nat ", reqid: 297
*May 1 17:03:38.065: src NBMA: Spoke's Public IP
*May 1 17:03:38.065: src protocol: 172.168.1.5, dst protocol: 172.168.1.3
*May 1 17:03:38.065: (C-1) code: no error(0)
*May 1 17:03:38.065: prefix: 32, mtu: 9972, hd_time: 7200
*May 1 17:03:38.066: addr_len: 0(NSAP), subaddr_len: 0(NSAP), proto_len: 0, pref: 255
*May 1 17:03:38.066: Responder Address Extension(3):
*May 1 17:03:38.066: Forward Transit NHS Record Extension(4):
*May 1 17:03:38.066: Reverse Transit NHS Record Extension(5):
*May 1 17:03:38.066: Authentication Extension(7):
*May 1 17:03:38.066: type:Cleartext(1), data:IBCVPN
*May 1 17:03:38.066: NAT address Extension(9):
*May 1 17:03:38.066: (C-1) code: no error(0)
*May 1 17:03:38.066: prefix: 32, mtu: 9972, hd_time: 0
*May 1 17:03:38.066: addr_len: 4(NSAP), subaddr_len: 0(NSAP), proto_len: 4, pref: 255
*May 1 17:03:38.066: client NBMA: Hub's Public IP
*May 1 17:03:38.066: client protocol: 172.168.1.3
*May 1 17:03:38.066: NHRP-DETAIL: Unable to get dst from pak sb
*May 1 17:03:38.066: NHRP: Encapsulation succeeded. Sending NHRP Control Packet NBMA Address: Hub's Public IP
*May 1 17:03:38.066: NHRP: 134 bytes out Tunnel0
*May 1 17:03:38.066: NHRP-RATE: Retransmitting Registration Request for 172.168.1.3, reqid 297, (retrans ivl 16 sec)
*May 1 17:03:45.203: ISAKMP: (0):DPD received KMI message.
*May 1 17:03:45.203: ISAKMP: (13612):set new node 182772557 to QM_IDLE
*May 1 17:03:45.203: ISAKMP-PAK: (13612):sending packet to Hub's Public IP my_port 500 peer_port 500 (I) QM_IDLE
*May 1 17:03:45.203: ISAKMP: (13612):Sending an IKE IPv4 Packet.
*May 1 17:03:45.203: ISAKMP: (13612):purging node 182772557
*May 1 17:03:45.228: ISAKMP-PAK: (13612):received packet from Hub's Public IP dport 500 sport 500 Global (I) QM_IDLE
*May 1 17:03:45.228: ISAKMP: (13612):set new node 3197197514 to QM_IDLE
*May 1 17:03:45.228: ISAKMP: (13612):processing HASH payload. message ID = 3197197514
*May 1 17:03:45.228: ISAKMP: (13612):deleting node 3197197514 error FALSE reason "Informational (in) state 1"
*May 1 17:03:45.228: ISAKMP: (13612):Input = IKE_MESG_FROM_PEER, IKE_INFO_NOTIFY
*May 1 17:03:45.228: ISAKMP: (13612):Old State = IKE_P1_COMPLETE New State = IKE_P1_COMPLETE
*May 1 17:03:51.481: NHRP: Setting retrans delay to 32 for nhs dst 172.168.1.3
*May 1 17:03:51.481: IPSEC-IFC MGRE/Tu0(Spoke's Public IP/Hub's Public IP): connection lookup returned 7F6263416268
*May 1 17:03:51.481: NHRP: Attempting to send packet through interface Tunnel0 via DEST dst 172.168.1.3
*May 1 17:03:51.481: NHRP: Send Registration Request via Tunnel0 vrf global(0x0), packet size: 106
*May 1 17:03:51.481: src: 172.168.1.5, dst: 172.168.1.3
*May 1 17:03:51.481: (F) afn: AF_IP(1), type: IP(800), hop: 255, ver: 1
*May 1 17:03:51.481: shtl: 4(NSAP), sstl: 0(NSAP)
*May 1 17:03:51.482: pktsz: 106 extoff: 52
*May 1 17:03:51.482: (M) flags: "unique nat ", reqid: 297
*May 1 17:03:51.482: src NBMA: Spoke's Public IP
*May 1 17:03:51.482: src protocol: 172.168.1.5, dst protocol: 172.168.1.3
*May 1 17:03:51.482: (C-1) code: no error(0)
*May 1 17:03:51.482: prefix: 32, mtu: 9972, hd_time: 7200
*May 1 17:03:51.482: addr_len: 0(NSAP), subaddr_len: 0(NSAP), proto_len: 0, pref: 255
*May 1 17:03:51.482: Responder Address Extension(3):
*May 1 17:03:51.482: Forward Transit NHS Record Extension(4):
*May 1 17:03:51.482: Reverse Transit NHS Record Extension(5):
*May 1 17:03:51.482: Authentication Extension(7):
*May 1 17:03:51.482: type:Cleartext(1), data:IBCVPN
*May 1 17:03:51.482: NAT address Extension(9):
*May 1 17:03:51.482: (C-1) code: no error(0)
*May 1 17:03:51.482: prefix: 32, mtu: 9972, hd_time: 0
*May 1 17:03:51.482: addr_len: 4(NSAP), subaddr_len: 0(NSAP), proto_len: 4, pref: 255
*May 1 17:03:51.482: client NBMA: Hub's Public IP
*May 1 17:03:51.482: client protocol: 172.168.1.3
*May 1 17:03:51.482: NHRP-DETAIL: Unable to get dst from pak sb
*May 1 17:03:51.482: NHRP: Encapsulation succeeded. Sending NHRP Control Packet NBMA Address: Hub's Public IP
*May 1 17:03:51.482: NHRP: 134 bytes out Tunnel0
*May 1 17:03:51.482: NHRP-RATE: Retransmitting Registration Request for 172.168.1.3, reqid 297, (retrans ivl 32 sec)
*May 1 17:03:59.230: ISAKMP: (0):DPD received KMI message.
*May 1 17:03:59.230: ISAKMP: (13612):set new node 2768883900 to QM_IDLE
*May 1 17:03:59.230: ISAKMP-PAK: (13612):sending packet to Hub's Public IP my_port 500 peer_port 500 (I) QM_IDLE
*May 1 17:03:59.230: ISAKMP: (13612):Sending an IKE IPv4 Packet.
*May 1 17:03:59.230: ISAKMP: (13612):purging node 2768883900
*May 1 17:03:59.257: ISAKMP-PAK: (13612):received packet from Hub's Public IP dport 500 sport 500 Global (I) QM_IDLE
*May 1 17:03:59.257: ISAKMP: (13612):set new node 1610289254 to QM_IDLE
*May 1 17:03:59.257: ISAKMP: (13612):processing HASH payload. message ID = 1610289254
*May 1 17:03:59.257: ISAKMP: (13612):deleting node 1610289254 error FALSE reason "Informational (in) state 1"
*May 1 17:03:59.257: ISAKMP: (13612):Input = IKE_MESG_FROM_PEER, IKE_INFO_NOTIFY
*May 1 17:03:59.257: ISAKMP: (13612):Old State = IKE_P1_COMPLETE New State = IKE_P1_COMPLETE

 

Hub's Log:

ISAKMP: (14288): SA life duration (basic) of 3600
*May 1 19:31:30.027: ISAKMP: (14288): SA life type in kilobytes
*May 1 19:31:30.027: ISAKMP: SA life duration (VPI) of 0x0 0x46 0x50 0x0
*May 1 19:31:30.027: ISAKMP: (14288): authenticator is HMAC-MD5
*May 1 19:31:30.027: ISAKMP: (14288): key length is 128
*May 1 19:31:30.027: ISAKMP: (14288):atts are acceptable.
*May 1 19:31:30.027: IPSEC(validate_proposal_request): proposal part #1,
(key eng. msg.) INBOUND local= Hub's Public IP:0, remote= Spoke's Public IP:0,
local_proxy= Hub's Public IP/255.255.255.255/47/0,
remote_proxy= Spoke's Public IP/255.255.255.255/47/0,
protocol= ESP, transform= esp-aes esp-md5-hmac (Transport),
lifedur= 0s and 0kb,
spi= 0x0(0), conn_id= 0, keysize= 128, flags= 0x0
*May 1 19:31:30.028: IPSEC(recalculate_mtu): reset sadb_root 7F5C6710F190 mtu to 1500
*May 1 19:31:30.028: (ipsec_process_proposal)Map Accepted: Tunnel0-head-0, 65542
*May 1 19:31:30.029: ISAKMP: (14288):processing NONCE payload. message ID = 4215411846
*May 1 19:31:30.029: ISAKMP: (14288):processing ID payload. message ID = 4215411846
*May 1 19:31:30.029: ISAKMP: (14288):processing ID payload. message ID = 4215411846
*May 1 19:31:30.029: ISAKMP: (14288):QM Responder gets spi
*May 1 19:31:30.029: ISAKMP: (14288):Node 4215411846, Input = IKE_MESG_FROM_PEER, IKE_QM_EXCH
*May 1 19:31:30.029: ISAKMP: (14288):Old State = IKE_QM_READY New State = IKE_QM_SPI_STARVE
*May 1 19:31:30.029: ISAKMP: (14288):Node 4215411846, Input = IKE_MESG_INTERNAL, IKE_GOT_SPI
*May 1 19:31:30.029: ISAKMP: (14288):Old State = IKE_QM_SPI_STARVE New State = IKE_QM_IPSEC_INSTALL_AWAIT
*May 1 19:31:30.029: IPSEC(crypto_ipsec_create_ipsec_sas): Map found Tunnel0-head-0, 65542
*May 1 19:31:30.030: IPSEC(crypto_ipsec_sa_find_ident_head): reconnecting with the same proxies and peer Spoke's Public IP
*May 1 19:31:30.031: IPSEC(crypto_ipsec_update_ident_tunnel_decap_oce): updating Tunnel0 ident 7F5C671118F8 with tun_decap_oce 7F5C5D0C5328
*May 1 19:31:30.031: IPSEC(get_old_outbound_sa_for_peer): No outbound SA found for peer 7F5C6711AA38
*May 1 19:31:30.032: IPSEC(create_sa): sa created,
(sa) sa_dest= Hub's Public IP, sa_proto= 50,
sa_spi= 0x29D82588(702031240),
sa_trans= esp-aes esp-md5-hmac , sa_conn_id= 10923
sa_lifetime(k/sec)= (4608000/3600),
(identity) local= Hub's Public IP:0, remote= Spoke's Public IP:0,
local_proxy= Hub's Public IP/255.255.255.255/47/0,
remote_proxy= Spoke's Public IP/255.255.255.255/47/0
*May 1 19:31:30.033: IPSEC(create_sa): sa created,
(sa) sa_dest= Spoke's Public IP, sa_proto= 50,
sa_spi= 0xB5AA954A(3047855434),
sa_trans= esp-aes esp-md5-hmac , sa_conn_id= 10924
sa_lifetime(k/sec)= (4608000/3600),
(identity) local= Hub's Public IP:0, remote= Spoke's Public IP:0,
local_proxy= Hub's Public IP/255.255.255.255/47/0,
remote_proxy= Spoke's Public IP/255.255.255.255/47/0
*May 1 19:31:30.037: ISAKMP-ERROR: (0):Failed to find peer index node to update peer_info_list
*May 1 19:31:30.037: ISAKMP: (14288):Received IPSec Install callback... proceeding with the negotiation
*May 1 19:31:30.037: ISAKMP: (14288):Successfully installed IPSEC SA (SPI:0x29D82588) on Tunnel0
*May 1 19:31:30.037: ISAKMP-PAK: (14288):sending packet to Spoke's Public IP my_port 500 peer_port 500 (R) QM_IDLE
*May 1 19:31:30.037: ISAKMP: (14288):Sending an IKE IPv4 Packet.
*May 1 19:31:30.038: ISAKMP: (14288):Node 4215411846, Input = IKE_MESG_FROM_IPSEC, IPSEC_INSTALL_DONE
*May 1 19:31:30.038: ISAKMP: (14288):Old State = IKE_QM_IPSEC_INSTALL_AWAIT New State = IKE_QM_R_QM2
*May 1 19:31:30.086: ISAKMP-PAK: (14288):received packet from Spoke's Public IP dport 500 sport 500 Global (R) QM_IDLE
*May 1 19:31:30.086: ISAKMP: (14288):deleting node 4215411846 error FALSE reason "QM done (await)"
*May 1 19:31:30.086: ISAKMP: (14288):Node 4215411846, Input = IKE_MESG_FROM_PEER, IKE_QM_EXCH
*May 1 19:31:30.086: ISAKMP: (14288):Old State = IKE_QM_R_QM2 New State = IKE_QM_PHASE2_COMPLETE
*May 1 19:31:30.086: IPSEC(key_engine_enable_outbound): rec'd enable notify from ISAKMP

*May 1 19:31:43.647: ISAKMP-PAK: (14288):received packet from Spoke's Public IP dport 500 sport 500 Global (R) QM_IDLE
*May 1 19:31:43.647: ISAKMP: (14288):set new node 3464596265 to QM_IDLE
*May 1 19:31:43.647: ISAKMP: (14288):processing HASH payload. message ID = 3464596265
*May 1 19:31:43.647: ISAKMP: (14288):deleting node 3464596265 error FALSE reason "Informational (in) state 1"
*May 1 19:31:43.647: ISAKMP: (14288):Input = IKE_MESG_FROM_PEER, IKE_INFO_NOTIFY
*May 1 19:31:43.647: ISAKMP: (14288):Old State = IKE_P1_COMPLETE New State = IKE_P1_COMPLETE

*May 1 19:31:43.647: ISAKMP: (14288):set new node 1346791607 to QM_IDLE
*May 1 19:31:43.648: ISAKMP-PAK: (14288):sending packet to Spoke's Public IP my_port 500 peer_port 500 (R) QM_IDLE
*May 1 19:31:43.648: ISAKMP: (14288):Sending an IKE IPv4 Packet.
*May 1 19:31:43.648: ISAKMP: (14288):purging node 1346791607
*May 1 19:31:43.648: ISAKMP: (14288):Input = IKE_MESG_FROM_PEER, IKE_MESG_KEEP_ALIVE
*May 1 19:31:43.648: ISAKMP: (14288):Old State = IKE_P1_COMPLETE New State = IKE_P1_COMPLETE

*May 1 19:32:07.697: ISAKMP-PAK: (14288):received packet from Spoke's Public IP dport 500 sport 500 Global (R) QM_IDLE
*May 1 19:32:07.698: ISAKMP: (14288):set new node 2884981883 to QM_IDLE
*May 1 19:32:07.698: ISAKMP: (14288):processing HASH payload. message ID = 2884981883
*May 1 19:32:07.698: ISAKMP: (14288):deleting node 2884981883 error FALSE reason "Informational (in) state 1"
*May 1 19:32:07.698: ISAKMP: (14288):Input = IKE_MESG_FROM_PEER, IKE_INFO_NOTIFY
*May 1 19:32:07.698: ISAKMP: (14288):Old State = IKE_P1_COMPLETE New State = IKE_P1_COMPLETE

*May 1 19:32:07.698: ISAKMP: (14288):set new node 3517296544 to QM_IDLE
*May 1 19:32:07.698: ISAKMP-PAK: (14288):sending packet to Spoke's Public IP my_port 500 peer_port 500 (R) QM_IDLE
*May 1 19:32:07.698: ISAKMP: (14288):Sending an IKE IPv4 Packet.
*May 1 19:32:07.699: ISAKMP: (14288):purging node 3517296544
*May 1 19:32:07.699: ISAKMP: (14288):Input = IKE_MESG_FROM_PEER, IKE_MESG_KEEP_ALIVE
*May 1 19:32:07.699: ISAKMP: (14288):Old State = IKE_P1_COMPLETE New State = IKE_P1_COMPLETE

*May 1 19:32:21.727: ISAKMP-PAK: (14288):received packet from Spoke's Public IP dport 500 sport 500 Global (R) QM_IDLE
*May 1 19:32:21.727: ISAKMP: (14288):set new node 699625417 to QM_IDLE
*May 1 19:32:21.727: ISAKMP: (14288):processing HASH payload. message ID = 699625417
*May 1 19:32:21.727: ISAKMP: (14288):deleting node 699625417 error FALSE reason "Informational (in) state 1"
*May 1 19:32:21.727: ISAKMP: (14288):Input = IKE_MESG_FROM_PEER, IKE_INFO_NOTIFY
*May 1 19:32:21.727: ISAKMP: (14288):Old State = IKE_P1_COMPLETE New State = IKE_P1_COMPLETE

*May 1 19:32:21.728: ISAKMP: (14288):set new node 407981745 to QM_IDLE
*May 1 19:32:21.728: ISAKMP-PAK: (14288):sending packet to Spoke's Public IP my_port 500 peer_port 500 (R) QM_IDLE
*May 1 19:32:21.728: ISAKMP: (14288):Sending an IKE IPv4 Packet.
*May 1 19:32:21.728: ISAKMP: (14288):purging node 407981745
*May 1 19:32:21.728: ISAKMP: (14288):Input = IKE_MESG_FROM_PEER, IKE_MESG_KEEP_ALIVE
*May 1 19:32:21.728: ISAKMP: (14288):Old State = IKE_P1_COMPLETE New State = IKE_P1_COMPLETE

in Spoke 
debug ip udp <<- did you see public IP of Hub with Port 500 ?
show crypto isakp sa <<- did you see correct public IP of Hub 
MHM

Hello,

at this point, if the problem still exists, I would just delete the tunnel interface on the spoke and recreate it. That sometimes solves these kind of issues. If it does not, I would erase the entire config of the router and reconfigure everything from scratch.

@Georg Pauwen 

I did try to delete the tunnel interface on Spoke and still having same issue. I do have MPLS connection between Hub and Spoke and that is working fine so do not want to mess that up.

Thank you for your suggestions though.

Review Cisco Networking for a $25 gift card