Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Hi,I would first clarify the failure scenario before implementing EEM → SSH → R2because there are actually several different failure cases here.You mention two scenarios:R1 has a WAN failure while R1 itself remains operational.R1 has a hardware failu...
Since the symptoms are consistent with a stale SA on R3 I think the next step is to verify whether initial-contact force is supported on R3 as well.If it is not supported please share the R3 model and IOS XE version so we can check the available IKEv...
Thanks,i would first check the exact ISR model and IOS XE version to confirm whether initial-contact force is available.if it is supported it is worth testing on R3 because your symptoms point to stale IPsec SA stateCisco documents initial-contact fo...
i would check the state at each evpn layer before calling this a bugshow device-tracking policy evpn-device-trackshow device-tracking policies interface <interface>show device-tracking database address 10.49.100.209show device-tracking database addre...
your findings make sense and the invalid spi message is consistent with the stale sa scenarioone thing i would also check on r3 is the ikev2 profile and whether initial-contact force command is applicablecisco documents that it forces initial contac...