cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2329
Views
0
Helpful
3
Replies

DMVPN: requires clear crypto sa

martinbuffleo
Level 1
Level 1

My DMVPN worked fine yesterday. However the DMVPN didn't come in. I left it for 20 with no joy.

Once I did a clear crypto sa on the spoke the tunnel came up.

This seems like I'm missing something in my config.

Can someone advise?

3 Replies 3

Marcin Latosiewicz
Cisco Employee
Cisco Employee

Oh ... well DPDs? Just wild speculation without config ;-)

Sorry my Spokes tunnel config is:

interface Tunnel0

description HO-VPN

bandwidth 100

ip address 10.x.250.6 255.255.255.0

no ip redirects

ip mtu 1400

ip nhrp authentication password

ip nhrp map multicast dynamic

ip nhrp map multicast publicIP

ip nhrp map 10.x.250.1 publicIP

ip nhrp network-id aNumber

ip nhrp holdtime 360

ip nhrp nhs 10.x.250.1

zone-member security Zone-TunnelToHO

ip ospf network broadcast

tunnel source FastEthernet4

tunnel mode gre multipoint

tunnel key aNumber

tunnel protection ipsec profile protect-gre

I think it's going to be something in crypto config, either invalid SPI recovery (alhough it's not strictly speaking required) or DPD missing (considering what you described and how you recovered).

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: