11-18-2015 10:30 AM - edited 03-05-2019 02:46 AM
I have configured IPSEC in a tunnel interface so as to encryot my traffic
Whenever I enable ipsec profile in Tunnel interface, The tunnel interface goes to reset mode. I tried shut and no shut but no luck
Can you please suggect the way forward and to resolve the issue please..
11-18-2015 01:31 PM
Please share relevent configuration
11-18-2015 09:41 PM
11-19-2015 03:17 PM
Sorry I am not that familiar with Flexvpn, I don't know if this document will halp you
http://www.cisco.com/c/en/us/support/docs/security/dynamic-multipoint-vpn-dmvpn/115726-flexvpn-hardmove-same-00.html
regards
Richard.
11-20-2015 02:12 AM
There is not quite enough config to check. Need to see the VRF config and config relating to the interfaces.
I would suggest doing a:
debug crypto ikev2
And I bet it will log an error which will make the problem look obvious.
11-20-2015 02:17 AM
Also you haven't quite gone full iWAN.
If you are doing it that way I think you are going to need an " ip nhrp map <head end tunnel ip> <head end physical interface ip>" on your spoke, otherwise the spoke wont be able to find the nhs server.
11-20-2015 05:18 AM
Hi Path
Yes you are right
It was something related to NHRP.
On A end and B end the nhs mapping i did with same IP which resulted in this error if you can see the configs, after correcting it got established.
Hope that this is the root cause.
Thanks for your time and support as well :)
Just one query, is there any chat session available 24*7 global wise for this support forum ?
11-20-2015 03:27 PM
It would be great if you could mark my answer as correct ... :-)
11-19-2015 01:43 AM
Hi Richard
Can you please update on below query please.
I am facing this issue with another device as well..
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide