12-04-2014 03:57 AM - edited 03-05-2019 12:17 AM
Hi
I have a problem with spoke router, which connected through the DMVPN tunnel to the hub (dmvpn phase 1).
Tunnel interface is Up, but encryption breaks from time to time (2-3 times per month). Ipsec connection establishment stops on phase 1 with state MM_NO_STATE.
Keys, profiles and isakmp policies are identical on both sides.
In debug output i see many attempts of retransmitting ISAKMP phase 1 and after that router deleting SA with reason "gen_ipsec_isakmp_delete but doi isakmp".
Internet link is working well and i can ping hub destination IP.
your thoughts?
thanks in advance
12-04-2014 05:56 AM
What devices and what installed IOS versions?
12-04-2014 06:09 AM
Hi Joseph,
cisco 2611XM (ADVIPSERVICESK9-M) - spoke - IOS Version 12.3(21)
cisco 7200 - hub - IOS Version 12.4(24)T4
12-04-2014 09:13 AM
Disclaimer
The Author of this posting offers the information contained within this posting without consideration and with the reader's understanding that there's no implied or expressed suitability or fitness for any purpose. Information provided is for informational purposes only and should not be construed as rendering professional advice of any kind. Usage of this posting's information is solely at reader's own risk.
Liability Disclaimer
In no event shall Author be liable for any damages whatsoever (including, without limitation, damages for loss of use, data or profit) arising out of the use or inability to use the posting's information even if Author has been advised of the possibility of such damage.
Posting
I've found the later IOS versions seem a bit more stable when doing IPSec tunnel stuff. Your (24)T4 version, I've found, isn't too bad, but if you can, you might consider upgrading the 3(21) version.
12-04-2014 10:16 AM
Joseph,
thanks you for advise. Definetly it could be good attempt to resolve this issue, but it is production router and IOS upgrade means - service degradation for some time, you know.
And nevertheless i think that this problem has another root cause...
12-04-2014 10:46 AM
Disclaimer
The Author of this posting offers the information contained within this posting without consideration and with the reader's understanding that there's no implied or expressed suitability or fitness for any purpose. Information provided is for informational purposes only and should not be construed as rendering professional advice of any kind. Usage of this posting's information is solely at reader's own risk.
Liability Disclaimer
In no event shall Author be liable for any damages whatsoever (including, without limitation, damages for loss of use, data or profit) arising out of the use or inability to use the posting's information even if Author has been advised of the possibility of such damage.
Posting
Yes, booting into new code will cause a service interruption, but only a few minutes. You're unable to schedule such?
Sure, it might have another cause, and for such, your best bet might be to work with TAC.
It's possible someone still might be able to suggest another cause, yet still, your spoke router, and its IOS, is a bit old.
BTW, since you running DMVPN, any other spokes? If so, same router models and/or IOS versions, or something newer? If there are other "newer" spokes, and if they are not having similar issues, it points toward this spoke router as the root of your problem.
12-04-2014 03:38 PM
Even few minutes sometimes can be expensive.. And surely if i will not have another way to fix it - i will do ios upgrade.
Yes, i have DMVPN on other spokes, some of them with the same router models and IOS versions and somethins newer. Issue only with that router
12-04-2014 05:34 PM
Disclaimer
The Author of this posting offers the information contained within this posting without consideration and with the reader's understanding that there's no implied or expressed suitability or fitness for any purpose. Information provided is for informational purposes only and should not be construed as rendering professional advice of any kind. Usage of this posting's information is solely at reader's own risk.
Liability Disclaimer
In no event shall Author be liable for any damages whatsoever (including, without limitation, damages for loss of use, data or profit) arising out of the use or inability to use the posting's information even if Author has been advised of the possibility of such damage.
Posting
Yes, any downtime can be expensive, but when you cannot spare 5 minutes in a scheduled (off-time) maintenance window, I'm surprised you don't have redundancy. There's also the chance of much more downtime if such a critical device fails.
12-04-2014 11:53 PM
Hello
.Try creating a new isakmp policy with a higher priority so when the lower policy drops(higher preference ) the new profile will negotiate if that is then stable remove the older policy
Have you applied debugging on isakmp if so does that show anything.
re
paul
12-05-2014 12:25 AM
Hi Paul,
thanks for idea, i will try it.
Yes i have applied debugging on isakmp and as i wrote In debug output i see many attempts of retransmitting ISAKMP phase 1 and after that router deleting SA with reason "gen_ipsec_isakmp_delete but doi isakmp".
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide