cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
664
Views
3
Helpful
5
Replies

DMVPN problem on Cisco ASR1006

sina.naser
Level 1
Level 1

Hi everyone,

When I configuring ASR1006 as a HUB in dmvpn network with ipsec profile, the dmvpn session with spokes didn't establish. When I do shut/no shut on tunnel of spoke side the problem solved. Even Without IPsec profile, We hadn't any problem. Debug ipsec isakmp and other debugs didnt show any results.

Sometimes after 30 minutes the problem solved automatically But after reload the router the problem still remains

I attached the hub & spoke configuration 

I appreciate any idea

Tnx in advance

5 Replies 5

that need more clarification, are you push default route via tunnel?
if not then try 
1-  if-state NHRP in Spoke 
2- iskamp keepalive in both Spoke and hub

Tnx for your reply. no i Use routing protocol for branches network.

I try these commands and inform you as soon as possible

 

I've tried these two command options but problem persists. It's so weird because we have another ASR1006 operational for many years with same configs.

can I see
show dmpvn detail 
 show crypto call admission statistics

There's nothing in the output of these commands.

I fixed the issue by the crypto isakmp invalid-spi-recovery command. It's a bug

https://www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/115801-technote-iosvpn-00.html