<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GRE tunnel flapping issue. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/gre-tunnel-flapping-issue/m-p/5203893#M1116303</link>
    <description />
    <pubDate>Sat, 05 Oct 2024 17:53:06 GMT</pubDate>
    <dc:creator>sutharhemant90</dc:creator>
    <dc:date>2024-10-05T17:53:06Z</dc:date>
    <item>
      <title>GRE tunnel flapping issue.</title>
      <link>https://community.cisco.com/t5/network-security/gre-tunnel-flapping-issue/m-p/5203835#M1116299</link>
      <description>&lt;P&gt;We are facing issue continues IPsec GRE tunnel flapping in case of backhaul link flapped. CPU going at the higher side and GRE Tunnels which are not enabled with crypto are stable.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;We have DC DR Solution&lt;/LI&gt;&lt;LI&gt;Branch to DC GRE tunnel created for ipsec.&lt;/LI&gt;&lt;LI&gt;DC core router are connected with ISP on BGP.&lt;/LI&gt;&lt;LI&gt;For branch we have used static route for DC WAN ip pool&lt;/LI&gt;&lt;LI&gt;Between DC to DR Point point link running over eigrp&lt;/LI&gt;&lt;LI&gt;Redistribution between eigrp to bgp and bgp to eigrp on DC and DR.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 05 Oct 2024 13:59:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/gre-tunnel-flapping-issue/m-p/5203835#M1116299</guid>
      <dc:creator>sutharhemant90</dc:creator>
      <dc:date>2024-10-05T13:59:14Z</dc:date>
    </item>
    <item>
      <title>Re: GRE tunnel flapping issue.</title>
      <link>https://community.cisco.com/t5/network-security/gre-tunnel-flapping-issue/m-p/5203839#M1116300</link>
      <description>&lt;P&gt;Check below&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sat, 05 Oct 2024 18:04:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/gre-tunnel-flapping-issue/m-p/5203839#M1116300</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-10-05T18:04:57Z</dc:date>
    </item>
    <item>
      <title>Re: GRE tunnel flapping issue.</title>
      <link>https://community.cisco.com/t5/network-security/gre-tunnel-flapping-issue/m-p/5203866#M1116301</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;
&lt;P&gt;Let's not jump to unwarranted conclusions, &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt; - we don't even know if what is flapping are interfaces themselves, or just some protocol running over them; we do not know enough about the tunnels and their configuration; we do not know if they are using any GRE tunnel keys already... in fact, GRE tunnel keys cannot cause a tunnel to flap. At most, they can cause it to never come up, but flapping as a process of coming up and down can not be traced down to GRE keys or absence of them.&lt;/P&gt;
&lt;P&gt;Hence, let's hold back on the compulsion to post a reply at every cost, and instead, let's collect actionable hard evidence beforehand.&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/127958"&gt;@sutharhemant90&lt;/a&gt; , I would like to ask you to share details from the device(s) where you see the tunnel flaps. I understand if some information cannot be shared openly - but please try to share as much as possible, anonymizing any sensitive information wherever needed.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;What is the platform and the operating system version on the device?&lt;/LI&gt;
&lt;LI&gt;Can you share the complete &lt;STRONG&gt;show logging&lt;/STRONG&gt; from the device? Please note - I'm looking for all logging messages, even those that may appear unrelated.&lt;/LI&gt;
&lt;LI&gt;Can you share the configuration of the device? The complete anonymized configuration would be ideal; at the very least, though, I would like to see the configuration of all tunnels, affected and unaffected, and the configuration of the BGP and EIGRP routing protocols including any route-maps, prefix lists or ACLs they may be referring to.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Thank you! Let's see if this information can move us further.&lt;/P&gt;
&lt;P&gt;Best regards,&lt;BR /&gt;Peter&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 05 Oct 2024 17:07:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/gre-tunnel-flapping-issue/m-p/5203866#M1116301</guid>
      <dc:creator>Peter Paluch</dc:creator>
      <dc:date>2024-10-05T17:07:59Z</dc:date>
    </item>
    <item>
      <title>Re: GRE tunnel flapping issue.</title>
      <link>https://community.cisco.com/t5/network-security/gre-tunnel-flapping-issue/m-p/5203892#M1116302</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/213786"&gt;@Peter Paluch&lt;/a&gt;&amp;nbsp; I have pasted some basic configuration from core router (IPs are changed*). I will check for logs and update.&lt;/P&gt;&lt;P&gt;Tunnel with IPsec Crypto Enabled. (Flapping tunnel when any ISP link going up\down)&lt;/P&gt;&lt;P&gt;interface Tunnel1001&lt;BR /&gt;bandwidth 4096&lt;BR /&gt;ip address x.x.x.x 255.255.255.252&lt;BR /&gt;tunnel source x.x.x.x&lt;BR /&gt;tunnel mode ipip&lt;BR /&gt;tunnel destination x.x.x.x&lt;BR /&gt;tunnel protection ipsec profile GRE&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Tunnel without IPsec Crypto Enabled. (Stable tunnel even if any isp links going up\down)&lt;/P&gt;&lt;P&gt;interface Tunnel1017&lt;BR /&gt;bandwidth 4096&lt;BR /&gt;ip address x.x.x.x 255.255.255.252&lt;BR /&gt;tunnel source x.x.x.x&lt;BR /&gt;tunnel mode ipip&lt;BR /&gt;tunnel destination x.x.x.x&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;-&lt;/P&gt;&lt;P&gt;router eigrp 110&lt;BR /&gt;variance 2&lt;BR /&gt;network 10.0.0.0&lt;BR /&gt;redistribute static&lt;BR /&gt;redistribute ospf 10 metric 512 1 255 1 1500&lt;BR /&gt;redistribute bgp 64940 metric 22528 1 255 1 1500&lt;/P&gt;&lt;P&gt;router bgp 64940&lt;BR /&gt;bgp log-neighbor-changes&lt;BR /&gt;neighbor 172.16.2.1 remote-as 9729&lt;BR /&gt;neighbor 172.16.2.1 description # BGP for ISP 1 #&lt;BR /&gt;neighbor 172.29.41.218 remote-as 55411&lt;BR /&gt;neighbor 172.29.41.218 description # BGP for ISP 1 #&lt;BR /&gt;!&lt;BR /&gt;address-family ipv4&lt;BR /&gt;redistribute static&lt;BR /&gt;redistribute eigrp 110&lt;BR /&gt;neighbor 172.16.2.1 activate&lt;BR /&gt;neighbor 172.16.2.1 weight 40000&lt;BR /&gt;neighbor 172.16.2.1 soft-reconfiguration inbound&lt;BR /&gt;neighbor 172.16.2.1 distribute-list ISP-1 in&lt;BR /&gt;neighbor 172.16.2.1 filter-list 70 out&lt;BR /&gt;neighbor 172.29.41.218 activate&lt;BR /&gt;neighbor 172.29.41.218 weight 40000&lt;BR /&gt;neighbor 172.29.41.218 soft-reconfiguration inbound&lt;BR /&gt;neighbor 172.29.41.218 distribute-list ISP-2 in&lt;BR /&gt;neighbor 172.29.41.218 filter-list 70 out&lt;BR /&gt;default-information originate&lt;BR /&gt;exit-address-family&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Cisco Version 17.10.1a&lt;BR /&gt;Cisco - ISR4461/K9&lt;/P&gt;</description>
      <pubDate>Sat, 05 Oct 2024 17:48:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/gre-tunnel-flapping-issue/m-p/5203892#M1116302</guid>
      <dc:creator>sutharhemant90</dc:creator>
      <dc:date>2024-10-05T17:48:57Z</dc:date>
    </item>
    <item>
      <title>Re: GRE tunnel flapping issue.</title>
      <link>https://community.cisco.com/t5/network-security/gre-tunnel-flapping-issue/m-p/5203893#M1116303</link>
      <description />
      <pubDate>Sat, 05 Oct 2024 17:53:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/gre-tunnel-flapping-issue/m-p/5203893#M1116303</guid>
      <dc:creator>sutharhemant90</dc:creator>
      <dc:date>2024-10-05T17:53:06Z</dc:date>
    </item>
    <item>
      <title>Re: GRE tunnel flapping issue.</title>
      <link>https://community.cisco.com/t5/network-security/gre-tunnel-flapping-issue/m-p/5203894#M1116304</link>
      <description>&lt;P&gt;Tunnel without IPSec profile dont use any kind of tunnel health check so that it always UP whenever destiantion is reachable (there is defualt route in rib)&lt;/P&gt;
&lt;P&gt;Tunnel with IPsec profile use isakmp keepalive and when keepalive is failed the tunnel is down even if destination is reachable.&lt;/P&gt;
&lt;P&gt;So your issue in your &lt;STRONG&gt;ISP&lt;/STRONG&gt; not your device.&lt;/P&gt;
&lt;P&gt;To be sure add ip sla to your defualt route and check the health of it.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sat, 05 Oct 2024 18:26:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/gre-tunnel-flapping-issue/m-p/5203894#M1116304</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-10-05T18:26:44Z</dc:date>
    </item>
    <item>
      <title>Re: GRE tunnel flapping issue.</title>
      <link>https://community.cisco.com/t5/network-security/gre-tunnel-flapping-issue/m-p/5203899#M1116305</link>
      <description>&lt;P&gt;Hello Hemant,&lt;/P&gt;
&lt;P&gt;Thank you for the information shared so far.&lt;/P&gt;
&lt;P&gt;From what I can tell so far, your configuration is &lt;STRONG&gt;not&lt;/STRONG&gt; GRE. Rather, you are using IP-in-IP tunnels, optionally with IPsec protection. It is not a problem in itself, but I wanted to point that out so that we share the common understanding of the details of your configuration.&lt;/P&gt;
&lt;P&gt;From the notes above, you wrote that the IPsec-protected tunnels flap &lt;U&gt;whenever any ISP link goes up or down&lt;/U&gt;. This is important - is the ISP link going up or down the only trigger for that tunnel flap?&lt;/P&gt;
&lt;P&gt;I'll still wait for the logs.&lt;/P&gt;
&lt;P&gt;Best regards,&lt;BR /&gt;Peter&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 05 Oct 2024 18:22:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/gre-tunnel-flapping-issue/m-p/5203899#M1116305</guid>
      <dc:creator>Peter Paluch</dc:creator>
      <dc:date>2024-10-05T18:22:15Z</dc:date>
    </item>
    <item>
      <title>Re: GRE tunnel flapping issue.</title>
      <link>https://community.cisco.com/t5/network-security/gre-tunnel-flapping-issue/m-p/5204131#M1116315</link>
      <description>&lt;P&gt;There are rare incidents when a tunnel starts flapping automatically without any connected link flapping issue. If there is flapping or if a down link comes up at the data center during this time, my tunnel will start flapping, leading to high CPU utilization. To address this, I have created a script to bring all GRE tunnels down and then start a few tunnels step by step.&lt;/P&gt;&lt;P&gt;For testing purposes, I have applied the following CLI to one branch where the tunnel is stable. However, I am still unsure about the potential unknown impacts and whether it is recommended to use this approach&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;crypto isakmp keepalive 3600 60 periodic&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Tunnel are not stable wherever keep alive timer is 20 10 Periodic&lt;/P&gt;</description>
      <pubDate>Sun, 06 Oct 2024 15:02:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/gre-tunnel-flapping-issue/m-p/5204131#M1116315</guid>
      <dc:creator>sutharhemant90</dc:creator>
      <dc:date>2024-10-06T15:02:28Z</dc:date>
    </item>
    <item>
      <title>Re: GRE tunnel flapping issue.</title>
      <link>https://community.cisco.com/t5/network-security/gre-tunnel-flapping-issue/m-p/5204340#M1116320</link>
      <description>&lt;P&gt;you mention GRE in your original post&lt;BR /&gt;and I think you typo use (please &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/127958"&gt;@sutharhemant90&lt;/a&gt;&amp;nbsp;confirm)&amp;nbsp;&lt;BR /&gt;tunnel mode IPIP&amp;nbsp;&lt;BR /&gt;remove it please&amp;nbsp;&lt;BR /&gt;for mode I will suggest mode depend on case you have&amp;nbsp;&lt;BR /&gt;which of below you have ?&lt;/P&gt;
&lt;P&gt;Regarding ISP did you use IP sla with default route or check link flapping?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GRE issue.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/230722iB3729A848D0FEF7B/image-size/large?v=v2&amp;amp;px=999" role="button" title="GRE issue.png" alt="GRE issue.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="P2MP.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/230723i75CAEB35792EAEF5/image-size/large?v=v2&amp;amp;px=999" role="button" title="P2MP.png" alt="P2MP.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Oct 2024 09:31:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/gre-tunnel-flapping-issue/m-p/5204340#M1116320</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-10-07T09:31:38Z</dc:date>
    </item>
    <item>
      <title>Re: GRE tunnel flapping issue.</title>
      <link>https://community.cisco.com/t5/network-security/gre-tunnel-flapping-issue/m-p/5204343#M1116321</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt; ,&lt;/P&gt;
&lt;BLOCKQUOTE&gt;you mention GRE in your original post&lt;BR /&gt;and I think you typo use&lt;BR /&gt;tunnel mode IPIP&lt;BR /&gt;remove it please&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;EM&gt;&lt;U&gt;&lt;STRONG&gt;NO! Absolutely NOT!&lt;BR /&gt;&lt;/STRONG&gt;&lt;/U&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;MHM, you cannot just blindly suggest that people change their existing working configurations! What is far more likely is that Hemant believes his tunnels are GRE-based but what has been configured &lt;STRONG&gt;and working&lt;/STRONG&gt; in his network is in reality IP-in-IP style of tunnels.&lt;/P&gt;
&lt;P&gt;Unless we have this clarified, no configuration shall be changed, and you, MHM, please stop and think before posting. This is already the second time I am asking you in this thread to avoid jumping into conclusions and stop replying compulsively without making sure you are, FIRST, factually correct, SECOND, that you are joining the discussion rather than hijacking it, THIRD, that you are cooperating instead of playing solo.&lt;/P&gt;
&lt;P&gt;Peter&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Oct 2024 07:30:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/gre-tunnel-flapping-issue/m-p/5204343#M1116321</guid>
      <dc:creator>Peter Paluch</dc:creator>
      <dc:date>2024-10-07T07:30:01Z</dc:date>
    </item>
    <item>
      <title>Re: GRE tunnel flapping issue.</title>
      <link>https://community.cisco.com/t5/network-security/gre-tunnel-flapping-issue/m-p/5204824#M1116340</link>
      <description>&lt;P&gt;Hello Hemant,&lt;/P&gt;
&lt;P&gt;A humble reminder for the logs - if it is possible to share them.&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;
&lt;P&gt;Best regards,&lt;BR /&gt;Peter&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Oct 2024 20:00:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/gre-tunnel-flapping-issue/m-p/5204824#M1116340</guid>
      <dc:creator>Peter Paluch</dc:creator>
      <dc:date>2024-10-07T20:00:10Z</dc:date>
    </item>
  </channel>
</rss>

