cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
626
Views
0
Helpful
2
Replies

BGP Routing halts once I've configured IPSEC on Border Routers

terryw1964
Level 1
Level 1

2025-08-13_20-53-28.jpg
I'm trying to lab Multi-Region Fabric.  But having an issue with my routing.


Before creating my tunnel interfaces and IPSEC encapsulation,   everything works as expected in regards to my routing. Which is completely BGP.  From the router at the 15201 site,  as well as the BizNet and PubInet routers, I can ping inside my core area, etc.  No issues.   But once I create my tunnels and the sdwan encapsulation configurations, things change.   

From the Router at the 15201 site, I can ping the inside interfaces of more core routers, but can not reach the rtr-Core-Biznet and rtr-Core-PubInet routers inside the core.   I've verified that icmp, dns, bgp etc are allowed under the interfaces within the SDWAN configuration portion of my config.

I'm learning, so it's possible I don't have something configured correctly    But to have the router from outside my core area to inside my core area working up until I apply  IPSEC, etc has me puzzled.

2 Replies 2

M02@rt37
VIP
VIP

Hello @terryw1964 

15201 site reach the BR-REG routers over the overlay IPs ?

 

Best regards
.ı|ı.ı|ı. If This Helps, Please Rate .ı|ı.ı|ı.

Run this 

Debug packet-trace condition source-ip <> bidirectional vpn0

Debug packet-trace start 

Show packet-tracer stats <<- share this 

MHM