08-03-2016 06:51 PM - edited 03-05-2019 04:26 AM
Hi everyone.
I've configured DMVPN with 200 spoke connect to 1 hub. But after 4 or 5 hours i need to ping from hub to some spoke to bring their DMVPN tunnel up. Here is my diagram :
Router 3845 => Checkpoint Nokika (use for Crypto)=>Spoke.
180 spokes work perfectly with same config.
08-03-2016 08:07 PM
Are you using the same software versions everywhere?
If traffic brings the VPN straight back up, do you actually have a problem?
08-03-2016 11:16 PM
i'm using same IOS.
Some of them need to clear crypto sa, some of them need to ping from HUB (HUB's tunnel source [IP]) to Spoke ( Spoke's tunnel Source [IP]) to bring tunnel up.
08-04-2016 05:14 PM
This smells a bit like an IOS issue. What IOS version are you running, and what are the 2 or 3 main routers you are using (e,g. Cisco 897, 2911, 4451)?
08-04-2016 07:21 PM
My Hub router is 3845 and spokes are 1861, 1841, 891.
i also think may be is IOS issue. But when i check with 4 devices have a same IOS, same config. Only 1 device need to be ping from hub to turn DMVPN tunnel on.
08-04-2016 07:22 PM
What IOS version are you using?
08-04-2016 07:40 PM
IOS
3845 : 12.4(24)T5
1841 : Version 15.1(4)M1, 12.4(24)T7
1861 : Version 12.4(24)T4
08-04-2016 07:46 PM
This is not a good mix. 15.14M10 is a gold star release, and available for all of the platforms mentioned above. I would recommend upgrading and moving to one release across all of your platforms to minimise issues.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide