12-23-2024 03:23 AM
I have configured multiple Tunnels and all my tunnels are very very slow.
My configuration is
HUB:
crypto isakmp policy 100
encr aes
authentication pre-share
group 2
crypto isakmp key Flatt01 address 0.0.0.0 0.0.0.0
crypto isakmp keepalive 60
!
!
crypto ipsec transform-set Internal esp-aes esp-sha-hmac
mode transport
!
crypto ipsec profile Internal
set transform-set Internal
interface Tunnel1
bandwidth 1000000
ip address 10.5.5.254 255.255.255.0
no ip redirects
ip mtu 1390
ip hold-time eigrp 10 60
no ip next-hop-self eigrp 10
no ip split-horizon eigrp 10
ip nhrp authentication Tiger
ip nhrp network-id 2
ip tcp adjust-mss 1360
delay 300
tunnel source GigabitEthernet0/0/0
tunnel mode gre multipoint
tunnel key 121
tunnel bandwidth transmit 100000
tunnel bandwidth receive 100000
tunnel protection ipsec profile Internal shared
Spoke:
crypto isakmp policy 100
encr aes
authentication pre-share
group 2
crypto isakmp key Flatt01 address 0.0.0.0 0.0.0.0
crypto isakmp keepalive 60
!
!
crypto ipsec transform-set Internal esp-aes esp-sha-hmac
mode transport
!
crypto ipsec profile Internal
set transform-set Internal
!
interface Tunnel1
ip address 10.5.5.30 255.255.255.0
no ip redirects
ip mtu 1370
ip authentication mode eigrp 10 md5
ip authentication key-chain eigrp 10 eigrp_keys
ip hold-time eigrp 10 60
ip nhrp authentication Tiger
ip nhrp map multicast dynamic
ip nhrp map 10.5.5.254 202.102.20.11
ip nhrp map multicast 202.102.20.11
ip nhrp network-id 2
ip nhrp holdtime 120
ip nhrp nhs 10.5.5.254
ip nhrp registration no-unique
tunnel source GigabitEthernet0
tunnel mode gre multipoint
tunnel key 121
tunnel protection ipsec profile Internal
my connectivity is ok but very very slow. i can access my network share and servers on hubside but the time it takes is killing me. i have change MTU and checked every tickbox i can find. Any suggestions???????
12-23-2024 03:55 AM - edited 12-23-2024 03:58 AM
Use
Ip mtu 1400
Ip tcp mss 1360
MHM
12-23-2024 07:34 AM
what is probably happening is fragmentation and reassembly.
set MSS with ip tcp adjust-mss 40 bytes lower than ip mtu
this is a comprehensive document on fragmentation and MTU issues.
**Please rate as helpful if this was useful**
12-23-2024 09:26 AM
Not related to your issue-
I would recommend looking into increasing your group level if possible. Recommended is a minimum of group 14 as anything lower is considered insecure.
12-23-2024 09:15 PM - edited 12-23-2024 09:18 PM
i have done this already (Ip mtu 1400, Ip tcp mss 1360) ping 10.5.5.254 size 1360 df-bit, gradually lowering it to 1260 just for checking but the problem still remains. My internet connections are very stable and good. Hub is 100MB and spoke is 20MB dedicated. i dont know how to clear this. i am stuck
Success rate is 40 percent (2/5), round-trip min/avg/max = 152/154/156 ms
12-23-2024 10:10 PM
You mention hub is 100 and spoke is 20' but how many spoke you have?
It can hub can not handle traffic and this lead to drop.
To be more sure ping from spoke to spoke see if there is any drop if there is not the dmvpn in spokes is healthy' the issue in hub and solution I think is using DIA to make spoke use WAN interface directly to access internet and use hub only to learn other spokes and to access HQ subnet.
MHM
12-23-2024 09:47 PM
sh interfaces tunnel 1
Tunnel1 is up, line protocol is up
Hardware is Tunnel
Internet address is 10.5.5.30/24
MTU 17912 bytes, BW 20000 Kbit/sec, DLY 50000 usec,
reliability 255/255, txload 13/255, rxload 1/255
Encapsulation TUNNEL, loopback not set
Keepalive not set
Tunnel linestate evaluation up
Tunnel source 192.168.15.200 (GigabitEthernet8)
Tunnel Subblocks:
src-track:
Tunnel1 source tracking subblock associated with GigabitEthernet8
Set of tunnels with source GigabitEthernet8, 1 member (includes iterators), on interface
Tunnel protocol/transport multi-GRE/IP
Tunnel TTL 255, Fast tunneling enabled
Tunnel transport MTU 1472 bytes
Tunnel transmit bandwidth 8000 (kbps)
Tunnel receive bandwidth 8000 (kbps)
Tunnel protection via IPSec
Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0
Output queue: 0/0 (size/max)
5 minute input rate 90000 bits/sec, 102 packets/sec
5 minute output rate 1079000 bits/sec, 125 packets/sec
1099 packets input, 128110 bytes, 0 no buffer
1318 packets output, 1284076 bytes, 0 underruns
when ping to direct internet interface of hub router
ping 202.102.20.11 repeat 100
Type escape sequence to abort.
Sending 100, 100-byte ICMP Echos to 202.102.20.11, timeout is 2 seconds:
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
Success rate is 100 percent (100/100), round-trip min/avg/max = 160/163/268 ms
But when i ping tunnel
ping 10.5.5.254
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.5.5.254, timeout is 2 seconds:
..!.!
Success rate is 40 percent (2/5), round-trip min/avg/max = 152/152/152 ms
12-23-2024 10:52 PM
Hub rate is
spoke to spoke problem still exits
my Hub interface output is
5 minute input rate 27787000 bits/sec, 4455 packets/sec
5 minute output rate 11112000 bits/sec, 3956 packets/sec
still got around 60 percent free.
HUB to spoke and spoke to spoke . all working at 40%. i am stuck
12-23-2024 11:33 PM
From spoke traceroute to other spoke
Do you see hub IP as hop in traceroute?
MHM
12-23-2024 11:53 PM
traceroute 172.3.6.1
Type escape sequence to abort.
Tracing the route to 172.3.6.1
VRF info: (vrf in name/id, vrf out name/id)
1 10.5.5.254 44 msec * *
2 *
10.5.5.36 68 msec *
traceroute from spoke to spoke completed successfully. working and showing 10.5.5.254 hub router also
12-25-2024 09:33 AM
Sorry I dont why my account in community not show the last reply in post I participate
ANYWAY
that wrong
do tracrotue three times
you must see the Hub in first traceroute and missing from second and third
the idea of PhaseII DMVPN is to form direct connect between Spoke-Spoke not making all traffic between Spokes pass through Hub this will add a huge load in Hub.
I think the mean reason of this case is wrong config of EIGRP
can I see EIGRP config in Hub and Spoke
MHM
12-25-2024 10:41 PM
Also i am not passing traffic from spoke to spoke. i want to access resources on hub from spoke
12-25-2024 09:13 PM
Hub
router eigrp 10
network 10.5.1.0 0.0.0.255
network 172.5.6.0 0.0.0.255
redistribute static
redistribute eigrp 2 metric 400 700 255 255 1400 route-map RouteFilter
passive-interface GigabitEthernet0/0/0
spoke
router eigrp 10
network 10.5.1.0 0.0.0.255
network 172.3.6.0 0.0.0.255
passive-interface Vlan1
eigrp stub connected
12-26-2024 07:44 AM
I send you PM
thanks
MHM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide