cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1835
Views
2
Helpful
13
Replies

DMVPN tunnel Very slow

lakhwaraa
Level 1
Level 1

I have configured multiple Tunnels and all my tunnels are very very slow.

My configuration is 
HUB: 

crypto isakmp policy 100
encr aes
authentication pre-share
group 2
crypto isakmp key Flatt01 address 0.0.0.0 0.0.0.0
crypto isakmp keepalive 60
!
!
crypto ipsec transform-set Internal esp-aes esp-sha-hmac
mode transport
!
crypto ipsec profile Internal
set transform-set Internal

interface Tunnel1
bandwidth 1000000
ip address 10.5.5.254 255.255.255.0
no ip redirects
ip mtu 1390
ip hold-time eigrp 10 60
no ip next-hop-self eigrp 10
no ip split-horizon eigrp 10
ip nhrp authentication Tiger
ip nhrp network-id 2
ip tcp adjust-mss 1360
delay 300
tunnel source GigabitEthernet0/0/0
tunnel mode gre multipoint
tunnel key 121
tunnel bandwidth transmit 100000
tunnel bandwidth receive 100000
tunnel protection ipsec profile Internal shared

 

Spoke: 

crypto isakmp policy 100
encr aes
authentication pre-share
group 2
crypto isakmp key Flatt01 address 0.0.0.0 0.0.0.0
crypto isakmp keepalive 60
!
!
crypto ipsec transform-set Internal esp-aes esp-sha-hmac
mode transport
!
crypto ipsec profile Internal
set transform-set Internal

!
interface Tunnel1
ip address 10.5.5.30 255.255.255.0
no ip redirects
ip mtu 1370
ip authentication mode eigrp 10 md5
ip authentication key-chain eigrp 10 eigrp_keys
ip hold-time eigrp 10 60
ip nhrp authentication Tiger
ip nhrp map multicast dynamic
ip nhrp map 10.5.5.254 202.102.20.11
ip nhrp map multicast 202.102.20.11
ip nhrp network-id 2
ip nhrp holdtime 120
ip nhrp nhs 10.5.5.254
ip nhrp registration no-unique
tunnel source GigabitEthernet0
tunnel mode gre multipoint
tunnel key 121
tunnel protection ipsec profile Internal

my connectivity is ok but very very slow. i can access my network share and servers on hubside but the time it takes is killing me. i have change MTU and checked every tickbox i can find. Any suggestions???????

 

13 Replies 13

Use 

Ip mtu 1400

Ip tcp mss 1360

MHM

what is probably happening is fragmentation and reassembly.

set MSS with ip tcp adjust-mss 40 bytes lower than ip mtu

https://www.cisco.com/c/en/us/support/docs/ip/generic-routing-encapsulation-gre/25885-pmtud-ipfrag.html

this is a comprehensive document on fragmentation and MTU issues.

**Please rate as helpful if this was useful**

Not related to your issue-

I would recommend looking into increasing your group level if possible. Recommended is a minimum of group 14 as anything lower is considered insecure.

lakhwaraa
Level 1
Level 1

i have done this already (Ip mtu 1400, Ip tcp mss 1360) ping 10.5.5.254 size 1360 df-bit, gradually lowering it to 1260 just for checking but the problem still remains. My internet connections are very stable and good. Hub is 100MB and spoke is 20MB dedicated. i dont know how to clear this. i am stuck
Success rate is 40 percent (2/5), round-trip min/avg/max = 152/154/156 ms

You mention hub is 100 and spoke is 20' but how many spoke you have?

It can hub can not handle traffic and this lead to drop.

To be more sure ping from spoke to spoke see if there is any drop if there is not the  dmvpn in spokes is healthy' the issue in hub and solution I think is using DIA to make spoke use WAN interface directly to access internet and use hub only to learn other spokes and to access HQ subnet.

MHM

lakhwaraa
Level 1
Level 1

sh interfaces tunnel 1
Tunnel1 is up, line protocol is up
Hardware is Tunnel
Internet address is 10.5.5.30/24
MTU 17912 bytes, BW 20000 Kbit/sec, DLY 50000 usec,
reliability 255/255, txload 13/255, rxload 1/255
Encapsulation TUNNEL, loopback not set
Keepalive not set
Tunnel linestate evaluation up
Tunnel source 192.168.15.200 (GigabitEthernet8)
Tunnel Subblocks:
src-track:
Tunnel1 source tracking subblock associated with GigabitEthernet8
Set of tunnels with source GigabitEthernet8, 1 member (includes iterators), on interface
Tunnel protocol/transport multi-GRE/IP
Tunnel TTL 255, Fast tunneling enabled
Tunnel transport MTU 1472 bytes
Tunnel transmit bandwidth 8000 (kbps)
Tunnel receive bandwidth 8000 (kbps)
Tunnel protection via IPSec
Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0
Output queue: 0/0 (size/max)
5 minute input rate 90000 bits/sec, 102 packets/sec
5 minute output rate 1079000 bits/sec, 125 packets/sec
1099 packets input, 128110 bytes, 0 no buffer
1318 packets output, 1284076 bytes, 0 underruns

when ping to direct internet interface of hub router
ping 202.102.20.11 repeat 100
Type escape sequence to abort.
Sending 100, 100-byte ICMP Echos to 202.102.20.11, timeout is 2 seconds:
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
Success rate is 100 percent (100/100), round-trip min/avg/max = 160/163/268 ms

But when i ping tunnel
ping 10.5.5.254
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.5.5.254, timeout is 2 seconds:
..!.!
Success rate is 40 percent (2/5), round-trip min/avg/max = 152/152/152 ms

lakhwaraa
Level 1
Level 1

Hub rate is 
spoke to spoke problem still exits
my Hub interface output is
5 minute input rate 27787000 bits/sec, 4455 packets/sec
5 minute output rate 11112000 bits/sec, 3956 packets/sec

still got around 60 percent free. 
HUB to spoke and spoke to spoke . all working at 40%. i am stuck

From spoke traceroute to other spoke

Do you see hub IP as hop in traceroute?

MHM

lakhwaraa
Level 1
Level 1

traceroute 172.3.6.1
Type escape sequence to abort.
Tracing the route to 172.3.6.1
VRF info: (vrf in name/id, vrf out name/id)
1 10.5.5.254 44 msec * *
2 *
10.5.5.36 68 msec *
traceroute from spoke to spoke completed successfully. working and showing 10.5.5.254 hub router also

Sorry I dont why my account in community not show the last reply in post I participate

ANYWAY 
that wrong

do tracrotue three times
you must see the Hub in first traceroute and missing from second and third 
the idea of PhaseII DMVPN is to form direct connect between Spoke-Spoke not making all traffic between Spokes pass through Hub this will add a huge load in Hub.

I think the mean reason of this case is wrong config of EIGRP 

can I see EIGRP config in Hub and Spoke 

MHM 

Also i am not passing traffic from spoke to spoke. i want to access resources on hub from spoke

lakhwaraa
Level 1
Level 1

Hub 
router eigrp 10
network 10.5.1.0 0.0.0.255
network 172.5.6.0 0.0.0.255
redistribute static
redistribute eigrp 2 metric 400 700 255 255 1400 route-map RouteFilter
passive-interface GigabitEthernet0/0/0

spoke
router eigrp 10
network 10.5.1.0 0.0.0.255
network 172.3.6.0 0.0.0.255
passive-interface Vlan1
eigrp stub connected

I send you PM 

thanks 

MHM