cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
300
Views
0
Helpful
1
Replies
Highlighted
Beginner

DMVPN tunnel goes down and would have to clear isakmp sa for it to come back up.

Hi guys Ive been noticing that my DMVPN setup has been having intermittent issues with sites  that are in transport mode.Every now and then I would have a site go down and would have to clear the isakmp sa session for it to come back up again. I have isakmp periodic keepalives configured and when I show my ISAKMP sa it shows multiple duplicate security associations. Can someone help?

 

My hub router is a ISR 4431 running version Version 15.5(3)S4b.

my spokes are ISR 2921 running version Version 15.5(3)M7

 

Below is the output of the show crypto isakmp sa with the duplicate sessions:

192.168.100.2 200.32.X.X QM_IDLE 1012 ACTIVE
192.168.100.2 200.32.X.X QM_IDLE 1010 ACTIVE
200.32.X.X 192.168.100.2 QM_IDLE 1013 ACTIVE
200.32.X.X 192.168.100.2 QM_IDLE 1011 ACTIVE

 

Ive noticed that my sites that are not using port forwarding aren't having this issue.

 

 

Everyone's tags (3)
1 REPLY 1
Highlighted
VIP Mentor

Re: DMVPN tunnel goes down and would have to clear isakmp sa for it to come back up.

Since we do not what is the hardware and IOs code you running and your high level network diagram to suggest what is wrong.

 

here is basic steps i can suggest to mitigate the issue (it would be nice if you can provide basic information and config to suggest better)

 

https://www.cisco.com/c/en/us/support/docs/security/dynamic-multipoint-vpn-dmvpn/111976-dmvpn-troubleshoot-00.html

 

BB
*** Rate All Helpful Responses ***