I have a Cisco 2911 (IOS ver 15.3(3)M) in our branch office and Cisco 7204VXR (IOS version 12.4(4)) in our headquarters. They should be connected to each other via IPsec Tunnel over EIGRP.
On the Cisco 2911, I receive this from the log:
Nov 17 17:34:33: %CRYPTO-4-IKMP_NO_SA: IKE message from 220.127.116.11 has no SA and is not an initialization offer Nov 17 17:51:21: %LINEPROTO-5-UPDOWN: Line protocol on Interface Tunnel65, changed state to down Nov 17 17:51:21: %DUAL-5-NBRCHANGE: EIGRP-IPv4 89: Neighbor 10.255.255.65 (Tunnel65) is down: interface down Nov 17 17:51:21: %LINEPROTO-5-UPDOWN: Line protocol on Interface Tunnel65, changed state to up Nov 17 17:51:25: %DUAL-5-NBRCHANGE: EIGRP-IPv4 89: Neighbor 10.255.255.65 (Tunnel65) is up: new adjacency
On the Cisco 7204, this is the log:
Nov 17 17:47:18: %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=18.104.22.168, prot=50, spi=0xA8A632E(176841518), srcaddr=22.214.171.124 Nov 17 17:47:19: %LINEPROTO-5-UPDOWN: Line protocol on Interface Tunnel6301, changed state to down Nov 17 17:47:19: %DUAL-5-NBRCHANGE: IP-EIGRP(0) 89: Neighbor 10.255.255.66 (Tunnel6301) is down: interface down Nov 17 17:47:21: %LINEPROTO-5-UPDOWN: Line protocol on Interface Tunnel6301, changed state to up Nov 17 17:47:23: %DUAL-5-NBRCHANGE: IP-EIGRP(0) 89: Neighbor 10.255.255.66 (Tunnel6301) is up: new adjacency
interface GigabitEthernet0/1 description internet ip address 126.96.36.199 255.255.255.192 ip access-group firewall in no ip redirects no ip unreachables no ip proxy-arp ip virtual-reassembly duplex full speed 100 media-type rj45 negotiation auto crypto map eq-ipsec
“Catalyst 8500 Series - Deep Dive”
This event will have place on Tuesday 17th, November 2020 at 10hrs PDT
The Catalyst 8500 Series Edge Platforms are built with the highly programmable, third-generation Cisco Quantum Flow Processor and designed for ...
“Catalyst 8000 Edge Platforms Family Overview”
This event will have place on Wednesday 4th, November 2020 at 10hrs PDT
Designed for an intent-based networks, the Cisco Catalyst 8000 Edge Platforms family offers best-in-class networking and security ...
I'm currently redistributing OSPF to BGP and setting a local pref on the routes. Currently this works fine and having no issues. ip prefix-list ospf-routes seq 10 permit 172.16.100.0/24
route-map ospf-bgp permit 10
match ip address prefix-list ...
Cisco SD-WAN Cloud OnRamp allows you to simplify and secure connectivity to cloud applications and public clouds. Interested in testing out the latest Cisco Cloud OnRamp solutions?
Sign up to try out various use cases with the Cisco SD-WAN Cloud ...
“Use Serviceability Features to Troubleshoot your Cat9K as a Cisco TAC Engineer”
This special event is open only to Cisco Customers and Partners.
Many pages in the Cisco Community are accessible only to Cisco customers, partners, or logged in ...