cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
383
Views
0
Helpful
7
Replies

[DMVPN] Need to ping from Hub to Spoke to turn DMVPN tunnel up

HDBank Network
Level 1
Level 1

Hi everyone.

I've configured DMVPN with 200 spoke  connect to 1 hub. But after 4 or 5 hours i need to ping from hub to some spoke to bring their DMVPN tunnel up. Here is my diagram :

Router 3845 => Checkpoint Nokika (use for Crypto)=>Spoke.

180 spokes work perfectly with same config.

7 Replies 7

Philip D'Ath
VIP Alumni
VIP Alumni

Are you using the same software versions everywhere?

If traffic brings the VPN straight back up, do you actually have a problem?

i'm using same IOS.

Some of them need to clear crypto sa, some of them need to ping from HUB (HUB's tunnel source [IP]) to Spoke ( Spoke's tunnel Source [IP]) to bring tunnel up.

This smells a bit like an IOS issue.  What IOS version are you running, and what are the 2 or 3 main routers you are using (e,g. Cisco 897, 2911, 4451)?

My Hub router is 3845 and spokes are 1861, 1841, 891.

i also think may be is IOS issue. But when i check with 4 devices have a same IOS, same config. Only 1 device need to be ping from hub to turn DMVPN tunnel on.

What IOS version are you using?

IOS

3845 : 12.4(24)T5

1841 : Version 15.1(4)M1, 12.4(24)T7

1861 : Version 12.4(24)T4

This is not a good mix.  15.14M10  is a gold star release, and available for all of the platforms mentioned above.  I would recommend upgrading and moving to one release across all of your platforms to minimise issues.

Review Cisco Networking products for a $25 gift card