cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1025
Views
5
Helpful
2
Replies

CSR 1000v nvram: pki cert not loading after reboot

philip moore
Level 1
Level 1

Dear community

 

I have encountered a problem with CSR 1000v. IOS-XE version 03.16.05.S/15.5(3)S5

 

When VM boots, sometimes the device fails to load PKI cert location in nvram. This causes DMVPN to not come up.

 

After router has started, I can manually re-apply the same commands and they are accepted.

 

What it looks like is that router rejects the nvram commands during startup. Perhaps nvram: is not available during boot process?

 

Has anyone else experienced this problem?

 

Thank you

 

running-config after boot:

 

crypto pki certificate chain sdn-network-infra-iwan

certificate ca 27820A9421D45FE1

                quit

 

Startup-config:

 

crypto pki certificate chain sdn-network-infra-iwan

certificate 20F390D0B8B90B35 nvram:sdn-network-#B35.cer

certificate ca 27820A9421D45FE1 nvram:sdn-network-#5FE1CA.cer

 

1 Accepted Solution

Accepted Solutions

JP Miranda Z
Cisco Employee
Cisco Employee
Hi philip moore,

The issue you are describing sounds exactly like the following known issue:
CSCvd31118

Try upgrading your CSR1kv to Everest(16.6.4) or Denali(16.3.7).

Hope this info helps!!

Rate if helps you!!

-JP-

View solution in original post

2 Replies 2

JP Miranda Z
Cisco Employee
Cisco Employee
Hi philip moore,

The issue you are describing sounds exactly like the following known issue:
CSCvd31118

Try upgrading your CSR1kv to Everest(16.6.4) or Denali(16.3.7).

Hope this info helps!!

Rate if helps you!!

-JP-

Alright thanks very much. Will give it a try.