05-15-2023 03:41 AM
Hi everyone,
When I configuring ASR1006 as a HUB in dmvpn network with ipsec profile, the dmvpn session with spokes didn't establish. When I do shut/no shut on tunnel of spoke side the problem solved. Even Without IPsec profile, We hadn't any problem. Debug ipsec isakmp and other debugs didnt show any results.
Sometimes after 30 minutes the problem solved automatically But after reload the router the problem still remains
I attached the hub & spoke configuration
I appreciate any idea
Tnx in advance
05-15-2023 04:01 AM
that need more clarification, are you push default route via tunnel?
if not then try
1- if-state NHRP in Spoke
2- iskamp keepalive in both Spoke and hub
05-15-2023 04:15 AM
Tnx for your reply. no i Use routing protocol for branches network.
I try these commands and inform you as soon as possible
05-16-2023 10:37 PM
I've tried these two command options but problem persists. It's so weird because we have another ASR1006 operational for many years with same configs.
05-17-2023 03:16 PM
can I see
show dmpvn detail
show crypto call admission statistics
05-21-2023 02:06 AM
There's nothing in the output of these commands.
I fixed the issue by the crypto isakmp invalid-spi-recovery command. It's a bug
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide