09-01-2015 09:13 AM - edited 03-05-2019 02:12 AM
I have a Hub-and-Spoke system, and I am being asked a question I don't have an immediate answer to! If I have 2 (or more) spokes connecting using DMVPN to a single Hub, I know that dynamicaly-created tunnels between the spokes are set up as they are needed. Once they are there, if Sopoke A is talking directly to Spoke B and the connection to the Hub drops for whatever reason, how long does the Spoke-to-Spoke connection stay alive? Is there a way to check this? And is this a configurable setting?
Thanks,
Brian
09-01-2015 09:57 AM
Brian,
In DMVPN, there is in fact no real connection because neither GRE, nor NHRP, nor IPsec are connection oriented protocols. However, some of the state data created by NHRP and IPsec may persist for some time (GRE is entirely stateless and does not maintain any state).
NHRP creates tunnel-to-internet IP address mappings. By default, the holdtime for these mappings is 2 hours. This holdtime can be modified using the ip nhrp holdtime seconds command on the tunnel interface.
The default lifetime of IPsec Phase 1 (ISAKMP) security associations is 1 day. This can be modified using the lifetime command in a crypto isakmp policy configuration mode.
The default lifetime of IPsec Phase 2 (IPsec) security associations is 1 hour and 4500 MiB (i.e., 4608 MB) of data, whichever is reached sooner. This can be modified using the global crypto ipsec security-association lifetime command, or using the per-crypto-map or per-crypto-ipsec-profile command set security-association lifetime.
Once again, neither of these protocols truly maintains a "connection" but they do maintain some state that can be readily reused when a new packet is being sent from one spoke to another (or between a hub and a spoke).
Best regards,
Peter
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide