cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
909
Views
0
Helpful
3
Replies

DVTI config behind NAT routers

GrmOperations
Level 1
Level 1

Moved from policy vpn to routed vpn. IPsec is up, as well as a EIGRP neighborship, however the routing is down. I am unable to ping the other end of the tunnel. Any insight would be appreciated.

 

Site 1 - SOHO Nat Router - Internet - SOHO Nat Router - DVTI

 

site 1:

 

Interface: Tunnel0 Session status: UP-ACTIVE Peer: 24.228.X.X port 4500 IKE SA: local 192.168.1.160/4500 remote 24.228.X.X/4500 Active IPSEC FLOW: permit ip 0.0.0.0/0.0.0.0 0.0.0.0/0.0.0.0 Active SAs: 2, origin: crypto map

 

CE-R13Cisco_1811#sh crypto isakmp sa IPv4 Crypto ISAKMP SA dst src state conn-id slot status 24.228.X.X 192.168.1.160 QM_IDLE 2123 0 ACTIVE

 

interface Tunnel0

ip unnumbered Loopback1

tunnel source FastEthernet0

tunnel destination 24.228.X.X

tunnel mode ipsec ipv4

tunnel protection ipsec profile VTILABTEST 

 

CE-R13Cisco_1811#sh ip eig nei IP-EIGRP neighbors for process 7 H Address Interface Hold Uptime SRTT RTO Q Seq (sec) (ms) Cnt Num 0 172.16.168.1 Tu0 13 01:42:53 23 5000 0 9

 

CE-R13Cisco_1811#sh ip eig topology IP-EIGRP Topology Table for AS(7)/ID(15.73.18.11) Codes: P - Passive, A - Active, U - Update, Q - Query, R - Reply, r - reply Status, s - sia Status P 172.16.168.0/28, 1 successors, FD is 128256 via Connected, Loopback1 P 3.47.29.11/32, 1 successors, FD is 297372416 via 172.16.168.1 (297372416/128256), Tunnel0 P 15.73.18.11/32, 1 successors, FD is 128256 via Connected, Loopback0 P 192.168.0.0/24, 0 successors, FD is Inaccessible via 172.16.168.1 (297244672/2816), Tunnel0 P 192.168.1.0/24, 1 successors, FD is 28160 via Connected, FastEthernet0 P 192.168.255.252/30, 1 successors, FD is 297246976 via 172.16.168.1 (297246976/28160), Tunnel0

 

CE-R13Cisco_1811#ping 172.16.168.1 Type escape sequence to abort. Sending 5, 100-byte ICMP Echos to 172.16.168.1, timeout is 2 seconds: ..... Success rate is 0 percent (0/5)

-------------------

 

Interface: Virtual-Access1 Profile: VTILABTEST Session status: UP-ACTIVE Peer: 24.47.X.X port 4500 Session ID: 0 IKEv1 SA: local 192.168.0.25/4500 remote 24.47.X.X/4500 Active IPSEC FLOW: permit ip 0.0.0.0/0.0.0.0 0.0.0.0/0.0.0.0 Active SAs: 2, origin: crypto map

 

CE-Cisco_2911HUB#sh crypto isakmp sa IPv4 Crypto ISAKMP SA dst src state conn-id status 192.168.0.25 24.47.X.X QM_IDLE 1005 ACTIVE

 

interface Virtual-Template1

type tunnel ip unnumbered Loopback5 

tunnel source GigabitEthernet0/0

tunnel mode ipsec ipv4

tunnel destination dynamic tunnel protection ipsec profile VTILABTEST

 

CE-Cisco_2911HUB#sh ip eig nei EIGRP-IPv4 Neighbors for AS(7) H Address Interface Hold Uptime SRTT RTO Q Seq (sec) (ms) Cnt Num 0 172.16.168.2 Vi1 14 01:54:30 39 1494 0 8

 

CE-Cisco_2911HUB#sh ip eig top EIGRP-IPv4 Topology Table for AS(7)/ID(3.47.29.11) Codes: P - Passive, A - Active, U - Update, Q - Query, R - Reply, r - reply Status, s - sia Status P 3.47.29.11/32, 1 successors, FD is 128256 via Connected, Loopback0 P 192.168.0.0/24, 1 successors, FD is 2816 via Connected, GigabitEthernet0/0 P 172.16.168.0/28, 1 successors, FD is 128256 via Connected, Loopback5 P 192.168.1.0/24, 0 successors, FD is Infinity via 172.16.168.2 (26882560/28160), Virtual-Access1 P 192.168.255.252/30, 1 successors, FD is 28160 via Connected, Vlan87 P 15.73.18.11/32, 1 successors, FD is 27008000 via 172.16.168.2 (27008000/128256), Virtual-Access1

 

CE-Cisco_2911HUB#ping 172.16.168.2 Type escape sequence to abort. Sending 5, 100-byte ICMP Echos to 172.16.168.2, timeout is 2 seconds: ..... Success rate is 0 percent (0/5)

 

1 Accepted Solution

Accepted Solutions

Have you defined the subnet mask of the loopback interfaces used for the tunnel as a /28 on both routers? Change it to a /32 on both routers then check your routing table again

View solution in original post

3 Replies 3

Hi,
The formatting of the output makes it hard to follow. I can see the pings are failing, but can you ping the other peer's router BUT from the source of the local router's tunnel loopback interface.

Can you upload the output of "show crypto session detail" please

CE-Cisco_2911HUB#show crypto session detail
Crypto session current status

Code: C - IKE Configuration mode, D - Dead Peer Detection
K - Keepalives, N - NAT-traversal, T - cTCP encapsulation
X - IKE Extended Authentication, F - IKE Fragmentation
R - IKE Auto Reconnect

Interface: Virtual-Access1
Profile: VTILABTEST
Uptime: 02:25:44
Session status: UP-ACTIVE
Peer: 24.47.X.X port 4500 fvrf: (none) ivrf: (none)
Phase1_id: 192.168.1.160
Desc: (none)
Session ID: 0
IKEv1 SA: local 192.168.0.25/4500 remote 24.47.X.X/4500 Active
Capabilities:N connid:1005 lifetime:21:34:15
IPSEC FLOW: permit ip 0.0.0.0/0.0.0.0 0.0.0.0/0.0.0.0
Active SAs: 2, origin: crypto map
Inbound: #pkts dec'ed 1868 drop 0 life (KB/Sec) 4340013/1739
Outbound: #pkts enc'ed 1903 drop 0 life (KB/Sec) 4340005/1739

CE-Cisco_2911HUB#ping 172.16.168.2 source loop 5
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 172.16.168.2, timeout is 2 seconds:
Packet sent with a source address of 172.16.168.1

CE-Cisco_2911HUB#sh ip cef 172.16.168.2
172.16.168.0/28
attached to Loopback5

Have you defined the subnet mask of the loopback interfaces used for the tunnel as a /28 on both routers? Change it to a /32 on both routers then check your routing table again