10-13-2009 03:05 AM - edited 03-04-2019 06:21 AM
Hi,
I am trying to use our 6509 chassis with a Sup32 Supervisor as a DMVPN hub.
The MSFC card has 2 Vlans configured (for simplicity) - One public facing (tunnel endpoint) and one internal.
I can initiate the Tunnel and it comes up fine. I can ping the remote router from the MSFC with the internal vlan as a source address and get a reply.
However, if I try and ping the remote router from a PC on the inernal lan, there is no reply.
I am seeing these errors on the remote router:-
%CRYPTO-4-RECVD_PKT_NOT_IPSEC: Rec'd packet not an IPSEC packet. (ip) vrf/dest_addr= /E.E.E.E, src_addr= e.e.e.e, prot= 47...
E = external address of remote router
e = external address on MSFC
From my reading, I think this is all down to intervlan routing being carried out by the MSFC\6509.
Has anybody had this issue and resolved it?
Any tips on how I can get this setup to work?
Thanks
Asad
10-13-2009 03:33 AM
Seems like a major configuration problem, review DMVPN documentation and correct your configuration accordingly.
10-13-2009 03:40 AM
I am happy that the DMVPN side is fine.
The hub config is same as my existing hub. I can see routes being advertised over the tunnel. And I can ping both ends of the tunnel over the routers.
The 6509 is currently running hybrid OS.
Do I need to look into using VRF?
10-13-2009 04:13 AM
How are you doing encryption on the catalyst ?
If not using a service module, you would be better using a regular ISR for dmvpn.
10-13-2009 06:17 AM
The Supervisor 32 module is doing the encryption (on the MSFC).
We currently are using a 3745 as the DMVPN hub, with around 10 spokes. However, the CPU usage is maxing out, causing some drops. The plan was to use the Sup32 (and greater processing power) as the hub and replace the 3745 altogther.
The other alternative is to purchase a 3845, but this will cost in the region of £7000
10-13-2009 06:28 AM
I think you will find that MSFC has less processing power than the 3745, and I wasn't even aware that it supported software encryption. In fact, the remote router is complaining that is not encrypting anything.
Any ISR router has onboard crypto HW and most likely you will not need a a 3845. I've had excellent results with just 1841s as hub device.
10-13-2009 06:44 AM
The MSFC is running advipservices which does support DMVPNs. The tunnel is up, with cryto sessions active, so it is encrypting. As I said, I can ping over the tunnel. What's not being encrypted is traffic from different VLANs, hence my question regarding VRF etc.
As you werent even aware that it supported software encryption, can you show me where it says that a Sup32 has LESS processing power than a 3745?
You state a 1841 would be fine, but if a 3745 is struggling, how would a 1841 cope any better? In any case, a 1841 would not suit us as we requre at least 6 interfaces on the router.
10-13-2009 06:48 AM
Because it has hardware crypto acceleration on-board by default, that's the point you are missing.
Neither 3745 nor MSFC has that, making them poor choices for IPsec.
10-13-2009 06:59 AM
Being unable to get 6 interfaces on a 1841 means its not an option. In addition to this, I cannot find a rating of its performance. This router needs to be able to route to our MPLS cloud (34M) and the internet (20M) so needs to be able to handle high throughput (1841 is geared for branch offices)
The 3745 is currently at the edge of its power with our 10 spokes. the newer 3845 with its faster processor etc should be able to handle the tunnels with ease.
All I am trying to do is see if I can use our existing equipment to act as the hub.
The tunnel is up so I know it can do DMVPN. I just need to work out a way to route other VLANS through the tunnel, rather that it switching.
10-13-2009 07:07 AM
I did not imply that you have to get a 1841, I was just making an example. However, from marketing material it can hande up to 45 mbps of encrypted traffic, meeting or exceeding your requirements.
You can also see that the only rating for 6500 switches is when equipped with optional VPN modules. I've never heard of anyone running IPSEC on the MSFC in a production environment.
If your objective is reusing existing hardware that is all good with me, but do not expect to get good results also.
10-13-2009 07:13 AM
The plan is to try and get this working and see what results we get.
If indeed, I cannot get the throughput required, or the 6509 too maxxes out on the CPU then the next step would be to get a 3845 with a VPN module etc.
10-13-2009 07:18 AM
Again, you do not need a VPN module with ISR routers. The onboard one is perfectly adequate for most uses.
10-13-2009 09:26 AM
From reading the posts . . .
If your 3745 doesn't have a crypto module, have you considered obtaining one? (e.g. AIM-VPN/HP II
10-13-2009 11:12 PM
The crypto module costs in the region of £2500. The 3745 is 7 years old so buying a module for it seems a bit unnecessary.
If I cant get this to work through the 6509, I will just get the 3845
10-14-2009 01:57 AM
Actually looking on the leading auctions site, this module can be bought for $50. Of course it is not worth to be bought new.
There are also reputable refurbished hardware dealer very helpful to those looking budget first.
Josephs suggestion is indeed a very valid one.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide