cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
404
Views
0
Helpful
3
Replies

spoke unable re-establish vpn tunnel when hub suffers line failure and line is restore

jomo frank
Level 1
Level 1

Hello expert,

I have hub and three spokes environment and I am using dmvpn for my tunnel.
I notice when my hub drop due to line disruption and service is restore
The  respected spokes are taken a very long time to re-establish the vpn
tunnel.
I enabled dead peer detection on the spokes to deal with issue but the tunnels
Still takes a long time to re-establish.
Can any one help me to resolve the above.

Regards
Jomo

3 Replies 3

rtjensen4
Level 4
Level 4

I think it might have to do with NHRP. The hub has to learn the NHRP mappings before it can build the tunnels. When the hub's interface goes down, those mappings are likely flushed. The Spokes have a static mapping to the Hub, but the hub has to learn about the spokes. I may be wrong, but I am guessing the delay is due to the interval that the spokes re-register NHRP with the hub.

You can configure ip nhrp holdtime on the spokes. The spokes will send an NHRP registration message every 1/3 the holdtime interval configured. This may speed up the process. HTH

http://blog.ine.com/2008/08/02/dmvpn-explained/

hello expert,

I sorry for the late reply but i was away on vacation.

I tried set the holdtime value to 60 seconds on both hub and spoke but the time taken to re-establish connection remain around 60minutes.

The only way i achieve a quick re-establishment of tunnel is to restart the spoke.

For a test enivorment this okay but in production enviroment where the spoke will be at remote location this is not practical.

Any other solution i am very anxious

Regards.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card