10-27-2019 02:04 AM
I have configured OSPF and GRE Tunnel 50 in HO & branch routers. All routers were working fine but suddenly from last month, one branch router starts giving below error and i lost connectivity.
%OSPF-5-ADJCHG: Process 3, Nbr 172.16.50.2 on Tunnel50 from FULL to DOWN, Neighbor Down: Dead timer expired .
then i have to shut reshut int vlan 50 & physical port to amke link up again. Problem comes back again after few hours or a day.
10-27-2019 03:18 AM
Since you have an OSPF interface configured on Tunnel, i suspect when the tunnel went down, the OSPF process terminated with a neighbour. investigate with Tunnel status and see any abnormal in the logs? both the side, since your logs only from one side.
10-27-2019 03:47 AM
Hello,
is this a DMVPN setup ? What kind of tunnel do you have configured, just a GRE tunnel, or an IPSec/GRE tunnel ? And what interface do you need to bounce ? Is the corresponding Internet link going down as well ? Is this branch configured like all other branches, and is the hardware and IOS identical to what you have at the other branches ?
In short, we need (a whole lot) more information...
10-27-2019 07:18 AM
10-27-2019 04:10 AM
Your message is not tunnel related issue but control-plane related issue.
OSPF dead timer expiration caused adjacency fault in your case. You have to understand why that happened.
This doesn't mean it's necessary a tunnel problem as in GRE tunneling is stateless. It means GRE doesn't test connectivity to bring up the tunnel. As long you have valid route in the rib for destination, tunnel goes always up unless you configure keepalives.
If in your HO you have kind of hub /spoke setup (P2MP on hub and P2P on spokes) and you use single tunnel to connect to all branch sites, then ,whatever the issue was, all sites would probably be impacted if the problem was caused by hub site.
As in your case the issue is related to a single branch i would first investigate remotely on that branch to see what's happening on the network:
For example, if you have latency on that link which is caused by peak of traffic which impacts the tunneled GRE ospf packets that would be a problem. It could be a QOS issue too if control-plane traffic is not well prioritized.
Or probably you have set too aggressive timer for that link which should be adjusted.
Regards
10-27-2019 07:26 AM
10-27-2019 10:21 AM
Since we are not aware of your setup you need to give us more information, and some topology, looking at the logs as mentioned. some of the interface gone down due to some reason, OSPF always relays on your underlay infrastructure to form and neighbourship.
can we know more information, how your network connected
Do you see some information here this interface gone down the same time? what is the interface? and where it is connected?
Oct 27 12:45:46: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet1, changed state to down
10-27-2019 10:41 PM
Each branch has 2 routers, one is connected to Mpls link and other is connected to Internet link.
This Router at branch is directly connected to MPLS link at port Fastethernet1, then it is connected to LAN Switch.
Internet router is connected to Firewall then from firewall it is connected to same LAN switch.
172.16.50.2 is the LAN port IP of HO router.
10-27-2019 02:51 PM
Hello,
is this a phase 2 or phase 3 DMVPN ? Is your OSPF configured as 'broadcast' network type?
10-27-2019 10:45 PM
10-28-2019 10:34 PM - edited 10-28-2019 10:36 PM
Hello
Can you please confirm the MTU values on the tunnel interfaces and also initiate a debug of the ospf adjacency and post the output.
sh ip interface tunnel x | in MTU
debug ip ospf adj
10-30-2019 11:02 PM
10-31-2019 01:36 AM
just curious to know - is this one? interface FastEthernet1 was going up and down?
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: