cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2718
Views
5
Helpful
6
Replies

DMVPN hub is down but still spoke to spoke tunnel is up...??

abhisar patil
Level 1
Level 1

Dear All,

We have DMVPN in our network with 1 hub and 3 spokes.When hub goes down spoke2 and spoke3 link doesnt goes down but
spoke 1 to spoke3 link goes down and spoke1 to spoke2 we have site to site VPN so doesnt goes down when hub is
down.

I want to know why spoke2 and spoke3 link is up when hub is down?


Also   we have configured static routes between spoke2 to spoke3 with next  hop  as tunnel ips of both the location.So is this the reason?and if so  then  how tunnel IPs are getting in routing table of spoke2 and spok3?

Abhisar.

1 Accepted Solution

Accepted Solutions

Hello Abhishar,

you have answered yourself your question: the key point is NHRP once the mapping of private address to public addres is done wiith static routes the spoke to spoke tunnel survives to HUB out of service. Dynamic routing would fail as it goes always via the HUB (vertical links to hub) and not over the dynamic spoke to spoke tunnel.

This is by design in DMVPN

Hope to help

Giuseppe

View solution in original post

6 Replies 6

ashok_boin
Level 5
Level 5

Hi Abhisar,

Can you please provide the relevant configs and ouputs from these routers?

And, are you able to reach (ping) from Site 2 to Site 3 in case of hub failure though the tunnels are up?

Regards...

-Ashok.


With best regards...
Ashok

Hi Ashok.

Thanks for your reply..

I got the answer, the concept behind this, is..

If you are using dynamic routing protocol inside the tunnels, you will loose your routes once the Hub failed so there is nothing you can do, spoke-2-spoke communication is lost.

If you are using static routing and If the spoke already has a NHRP entry before the hub failed, it will use it. But if the remote spoke public address changed in the meantime, it will not work as there is no HUB to answer to the NHRP resolution request.

Abhisar.

Hello Abhishar,

you have answered yourself your question: the key point is NHRP once the mapping of private address to public addres is done wiith static routes the spoke to spoke tunnel survives to HUB out of service. Dynamic routing would fail as it goes always via the HUB (vertical links to hub) and not over the dynamic spoke to spoke tunnel.

This is by design in DMVPN

Hope to help

Giuseppe

Thanks Giuseppe,

Ya I got the concept now.Also if you have any doc or link about DMVPN concepts, can please share here.

Abhisar.

Hello Abhisar,

the solution reference network design is a good document about DMVPN

see

http://www.cisco.com/en/US/docs/solutions/Enterprise/WAN_and_MAN/DMVPDG.html

also networkers slides, even of some years ago, are a very good source of information.

Hope to help

Giuseppe

Thanks Giuseppe.

I will get back toy you, for further issues regarding DMVPN.

Abhisar.

Review Cisco Networking for a $25 gift card