Showing results for 
Search instead for 
Did you mean: 
Join Customer Connection to register!


hi all ;


i need your help, advice.


i have a topology that include 1 hq and 2 sites.  i have 2 dmvpn tunnel. one is belongs to primary link of isp(tunnel 100), other one is belongs to backup link of isp(tunnel 200). tunnel 100 is running bgp, tunnel 200 is running eigrp. my problem is; when a site primery link goes down for exm:site 1. there is asiymetric route. site 1 tun 200 running eigrp, is forwarding packet to hq , hq is forwarding packet to site 2 . but via bgp(tunnel 100) (because site 2 is running still bgp(primary link of tunnel run bgp). and bgp ad is lower. and first chosie.that ok. but) site 2 is forwarding packet to site 1 directly via tunnel 200. (that i want. but site 1 is not forward trafic to site 2. i want they comminicate directly. ). i cant solve this. please advice me or hand me.

Giuseppe Larosa
Hall of Fame Master

Hello @BurakTutkun ,

what you would like to achieve is not an easy task.

In order to have the spokes to be able to speak directly on the only available tunnel when the primary tunnel fails you need to ensure that all the configuration tricks are configured.

For EIGRP you need:

no ip eigrp X split-horizon

no ip eigrp X next-hop self


on the hub router under interface tunnel 200.

But even with these tricks configured the eBGP route would be preferred over the EIGRP route for its lower AD.

One possible way to avoid this comparison would be to put the two tunnels in two different VRFs on the hub site so that if the primary link fails on a spoke the other spoke uses the secondary tunnel.

But this is not enough.Two different VRFs should be used also on the spokes and this would make the solution really complex.


I would suggest you to consider if the current setup can be acceptable for you (this depends on the number of spokes in the real network).


Hope to help




hi,i will try with vrf. but i need to ask that its possible configure vrf only at hub site. one is for tunne 100 other one is tunnel 200 ? i

hi, tunnel 100 is running bgp and primary isp link,eigrp running on tunnel 200 and secondary link(backup).normaly both link is up and tunnel 100 is running all traffic goes via tunnel 100. but problem is starting when one one of the sites primary link goes down. when primaty link goes down, for exp. site 1 , tunnel 200 is running . and forwarding traffic to hub. now i wait hub give site 2 nbma adress of the tunnel 200 . its normal for nhrp. but hq does not give site 2 nbma adress of tunnel 200. hq look the routing table . site 2 tunnel 100 is up and run bgp . for ad its forward traffic to site 2 via tunnel 1. untill now things okey. site 2 send a packet to site 1. packet goes to hq first for site 1 nbma of tunnel 200. its okey. hq gives the adress and site 2 setup a tunnel with site 1 directly. when i look at the site 1 routing table i cant see any route entry for site 2 networks. site 1 see only default route from hq. but site 2 see site 1 network advertisements. when i shut the interface of the site 1 primary link. all comminications is normal. and i can see site 2 networks on the aite 1 routing table. i think promlem is when site 1 primary link goes down. hq see site 1 networks from eigrp, site 2 network from bgp. site 1 send a packet to site . packet come to hq and hq know the networks on the site 2 from bgp. but site 2 send a packet to site 1 . packet come to hq. hq know networks on site 1 from eigrp. because site 1 bgp is down. there is a contrast.

So, each site has two tunnels connected to the isp.

Each having a Tunnel with BGP en a Tunnel based on EIGRP. You probably wan't to select the EIGRP as main...

So I understand that a tunnel goes down from a site, you HQ is sending out suddenly via the wrong Tunnel?...


To reach site 1, it is only able via the BGP tunnel to Site 2?

That is as far I understand correct behavior... But perhaps creating a fixed route with a higher AD can solve the issue.

It floats around until the tunnel goes down. You configure it to use the still active Tunnel if it is there.


I hope this is a good idea for you.