12-26-2023 11:22 AM
Hello Experts,
I am testing IPSEC tunnel failover in my virtual lab. I am using IOSv for this test. On the spoke router, I have two VRF-aware tunnels. Tunnel 10 uses vrf A and Tunnel 9 uses vrf B. I am using iBGP over the tunnel. Tunnel 10 uses the primary physical link gi0/1 and Tunnel 9 uses the secondary physical link gi0/2. Both my tunnels are up and I can reach the remote PC connected to the HUB router. I want to use Tunnel 10 as my primary tunnel and tunnel 9 as my backup tunnel. So I configured "backup interface tunnel 9" on tunnel 10 and gre keepalive which put tunnel 9 in standby mode and down. If I shut down the physical interface gi0/1, tunnel 10 doesn't go down and tunnel 9 keeps staying in standby mode and down. Could you let me know what I am doing wrong here, please? or point me to documentation.
12-26-2023 11:41 AM
Share topolgy and config of spoke
MHM
12-26-2023 11:51 AM
can you post topology and configuration here to check what is missing :
you can also achieve different method example :
12-27-2023 01:07 PM
I believe that the issue is how you are generating the failure: " If I shut down the physical interface gi0/1". My experience is that when using backup interface that if you shut down the interface the IOS says you intended the change and does not invoke the failover. I suggest that you unplug the interface and see if that does not activate the failover.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide