05-05-2020 11:32 AM
Hello Experts,
I have configured tunnel on both DR-WAN & A-WAN, the tunnel is up but i am unable to ping any tunnel ip. What i am trying to achieve is to send client SPR subnet from DR-WAN to A-WAN and vice versa through tunnel. So i would be advertising more subnets in vrf SPR. But now i am stuck with this issue. Please help
Please find my attached configs. Any help would be much appreciated.
Solved! Go to Solution.
05-05-2020 12:28 PM - edited 05-05-2020 12:31 PM
Hello
Looks like you not initiating ping in the correct place - Try ping within the vrf
ping vrf SPR ip 10.1.0.9x
05-06-2020 02:49 AM
Hi Nick,
One more thing you need to add is a tunnel key to each tunnel.
Example:-
int tunnel1
tunnel key 1
int tunnel2
tunnel key 2
05-05-2020 12:28 PM - edited 05-05-2020 12:31 PM
Hello
Looks like you not initiating ping in the correct place - Try ping within the vrf
ping vrf SPR ip 10.1.0.9x
05-05-2020 12:40 PM
Very good point from @paul driver. If that doesn't fix the issue then I have a couple requests
- can you ping the tunnel destination specifying the ping source as the tunnel source? For both routers.
- would you post the output of the commands on both routers
show ip osp interface
show ip ospf neighbor
05-06-2020 01:04 AM
Thankyou very much @Richard Burts and @paul driver for you help as i am not very good at vrf. Hence practising vrf with tunnel. Could you please help me with one more thing, don't know what i am missing here
Now when i created another tunnel(tunnel2) and ospf for vrf SB. My tunnel 1 is up but not able to advertise routes to A-WAN-R01 and vice versa and also not able to ping tunnel 1 ip. Below are the configs
Thanks
Nick
05-06-2020 02:49 AM
Hi Nick,
One more thing you need to add is a tunnel key to each tunnel.
Example:-
int tunnel1
tunnel key 1
int tunnel2
tunnel key 2
05-06-2020 02:54 AM
Hello @Meheretab Mengistu
I do agree the tunnel key command allows to multiplex / demultiplex the GRE packets of the different tunnels that are sharing the same external IP addresses and the same IPSec profile so an additional parameter is needed to discriminate packets of the two tunnels.
Best Regards
Giuseppe
05-06-2020 03:41 AM
Thankyou @Giuseppe Larosa @Meheretab Mengistu @Richard Burts @paul driver . Now i am able to form ospf neighbor ship for multiple vrf across their respective tunnel
DR-WAN-R01#sh ip ospf neighbor
Neighbor ID Pri State Dead Time Address Interface
10.123.124.98 0 FULL/ - 00:00:39 10.123.124.98 Tunnel2
10.1.0.98 0 FULL/ - 00:00:31 10.1.0.98 Tunnel1
Thanks
Nick
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide