cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1364
Views
5
Helpful
4
Replies

DMVPN Phase2 tunnel fails if Hub is reloaded

enewburn1
Level 1
Level 1

Hi,

  I have a weird issue and am wondering if anyone has any ideas about what may be wrong with my config. I have (2) ISR4Ks running Denali in a Hub and Spoke mGRE DMVPN solution. Everything works fine unless my Hub router is reloaded - at which point the DMVPN connection will fail and not return to service. Removing and reapplying the encryption profile on the Spoke end causes everything to start working again. Attached are the relevant(?) sections of the config from each. Any thoughts?

 

**Update** If I do nothing whatsoever about 25 minutes after the Hub has finished its reload the IPSEC SA will reform on its own

1 Accepted Solution

Accepted Solutions

enewburn1
Level 1
Level 1

Found the correct solution to the weirdness. Setting the tunnel's NHRP holdtime to 300 seconds did the trick. Now the tunnel and EIGRP association come up within a few seconds of each other

Thank you

View solution in original post

4 Replies 4

Hi,
You should configure dead peer detection (dpd), this will detect when the hub goes down and delete the old (down) tunnel after a period. Once the hub is back up a new tunnel should then allowed to be established, intiated from the spoke. Link here for info on dpd.

 

HTH

That sounds kinda cool!

I'll check that out and get back to you, thank you for the tip

 

**Update** Well I added "crypto isakmp keepalive 30 5" and reloaded the Hub - but still have the same symptoms as before. Still, I appreciate the recommendation - always good to learn new things

Hey RJI - the isakmp DPD didn't do the trick but it got me going in the right direction. Thanks again!

enewburn1
Level 1
Level 1

Found the correct solution to the weirdness. Setting the tunnel's NHRP holdtime to 300 seconds did the trick. Now the tunnel and EIGRP association come up within a few seconds of each other

Thank you

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: