03-26-2018 12:17 AM - edited 03-05-2019 10:09 AM
Hello Experts,
I implemented DMVPN and all spokes are working except one spoke.
on this HUB I am getting the error from this problemtic spoke:
%CRYPTO-4-IKMP_NO_SA: IKE message from xxx.xxx.xxx.xxx has no SA and is not an initialization offer
Info: Sometime tunnel comes up and then automatically goes down....so its not stable at all.
on HUB: sh cry isa sa
196.243.205.120 107.120.64.62 MM_SA_SETUP 0 ACTIVE
196.243.205.120 107.120.64.62 MM_SA_SETUP 0 ACTIVE
196.243.205.120 107.120.64.62 MM_NO_STATE 0 ACTIVE (deleted)
196.243.205.120 107.120.64.62 MM_NO_STATE 0 ACTIVE (deleted)
196.243.205.120 107.120.64.62 MM_NO_STATE 0 ACTIVE (deleted)
On Spoke: sh cry isa sa
196.243.205.120 107.120.64.62 MM_NO_STATE 0 ACTIVE (deleted)
196.243.205.120 107.120.64.62 MM_NO_STATE 0 ACTIVE (deleted)
what could be the reason!!!
Thanks in advance.
03-26-2018 01:24 AM
Hello,
does that spoke have a high amount of traffic compared to the other ones ? Try and configure:
crypto ipsec security-association lifetime kilobytes disable
03-26-2018 01:34 AM
yes it has more traffic then other spokes.
I configured the above command but still tunnels are not coming UP.
Thanks
03-26-2018 05:25 AM - edited 03-26-2018 05:26 AM
03-26-2018 05:25 AM
can anyone help ?
03-26-2018 07:58 AM
Hello,
is the IOS version and the hardware used at the 'problem' spoke different from the other spoke sites ? What about the ISP link ?
Post the full config of the spoke, we might be able to spot something...
03-26-2018 08:21 AM
The output of debug crypto isakmp on the spoke might have something helpful.
HTH
Rick
03-26-2018 10:24 PM - edited 02-11-2019 05:41 AM
Hi,
all spoke have same IOS version: c2900-universalk9-mz.SPA.155-3.M5.bin
ISP is ok, as it works for few hours(tunnel is up) and then automatically stop(tunnel down for few hours)
Thanks
03-27-2018 12:19 AM
Hello,
not sure if this has already been asked, but does the entire connection go down, or just the tunnel ?
Either way, try a lower replay window size:
crypto ipsec security-association replay window-size 512
03-27-2018 12:23 AM
Only Tunnel goes down.
At the moment tunnel is active from last 12 hours.
Thanks
04-29-2019 05:19 AM
03-26-2018 02:13 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide