06-25-2018 07:54 AM - edited 03-12-2019 05:24 AM
Moved from policy vpn to routed vpn. IPsec is up, as well as a EIGRP neighborship, however the routing is down. I am unable to ping the other end of the tunnel. Any insight would be appreciated.
Site 1 - SOHO Nat Router - Internet - SOHO Nat Router - DVTI
site 1:
Interface: Tunnel0 Session status: UP-ACTIVE Peer: 24.228.X.X port 4500 IKE SA: local 192.168.1.160/4500 remote 24.228.X.X/4500 Active IPSEC FLOW: permit ip 0.0.0.0/0.0.0.0 0.0.0.0/0.0.0.0 Active SAs: 2, origin: crypto map
CE-R13Cisco_1811#sh crypto isakmp sa IPv4 Crypto ISAKMP SA dst src state conn-id slot status 24.228.X.X 192.168.1.160 QM_IDLE 2123 0 ACTIVE
interface Tunnel0
ip unnumbered Loopback1
tunnel source FastEthernet0
tunnel destination 24.228.X.X
tunnel mode ipsec ipv4
tunnel protection ipsec profile VTILABTEST
CE-R13Cisco_1811#sh ip eig nei IP-EIGRP neighbors for process 7 H Address Interface Hold Uptime SRTT RTO Q Seq (sec) (ms) Cnt Num 0 172.16.168.1 Tu0 13 01:42:53 23 5000 0 9
CE-R13Cisco_1811#sh ip eig topology IP-EIGRP Topology Table for AS(7)/ID(15.73.18.11) Codes: P - Passive, A - Active, U - Update, Q - Query, R - Reply, r - reply Status, s - sia Status P 172.16.168.0/28, 1 successors, FD is 128256 via Connected, Loopback1 P 3.47.29.11/32, 1 successors, FD is 297372416 via 172.16.168.1 (297372416/128256), Tunnel0 P 15.73.18.11/32, 1 successors, FD is 128256 via Connected, Loopback0 P 192.168.0.0/24, 0 successors, FD is Inaccessible via 172.16.168.1 (297244672/2816), Tunnel0 P 192.168.1.0/24, 1 successors, FD is 28160 via Connected, FastEthernet0 P 192.168.255.252/30, 1 successors, FD is 297246976 via 172.16.168.1 (297246976/28160), Tunnel0
CE-R13Cisco_1811#ping 172.16.168.1 Type escape sequence to abort. Sending 5, 100-byte ICMP Echos to 172.16.168.1, timeout is 2 seconds: ..... Success rate is 0 percent (0/5)
-------------------
Interface: Virtual-Access1 Profile: VTILABTEST Session status: UP-ACTIVE Peer: 24.47.X.X port 4500 Session ID: 0 IKEv1 SA: local 192.168.0.25/4500 remote 24.47.X.X/4500 Active IPSEC FLOW: permit ip 0.0.0.0/0.0.0.0 0.0.0.0/0.0.0.0 Active SAs: 2, origin: crypto map
CE-Cisco_2911HUB#sh crypto isakmp sa IPv4 Crypto ISAKMP SA dst src state conn-id status 192.168.0.25 24.47.X.X QM_IDLE 1005 ACTIVE
interface Virtual-Template1
type tunnel ip unnumbered Loopback5
tunnel source GigabitEthernet0/0
tunnel mode ipsec ipv4
tunnel destination dynamic tunnel protection ipsec profile VTILABTEST
CE-Cisco_2911HUB#sh ip eig nei EIGRP-IPv4 Neighbors for AS(7) H Address Interface Hold Uptime SRTT RTO Q Seq (sec) (ms) Cnt Num 0 172.16.168.2 Vi1 14 01:54:30 39 1494 0 8
CE-Cisco_2911HUB#sh ip eig top EIGRP-IPv4 Topology Table for AS(7)/ID(3.47.29.11) Codes: P - Passive, A - Active, U - Update, Q - Query, R - Reply, r - reply Status, s - sia Status P 3.47.29.11/32, 1 successors, FD is 128256 via Connected, Loopback0 P 192.168.0.0/24, 1 successors, FD is 2816 via Connected, GigabitEthernet0/0 P 172.16.168.0/28, 1 successors, FD is 128256 via Connected, Loopback5 P 192.168.1.0/24, 0 successors, FD is Infinity via 172.16.168.2 (26882560/28160), Virtual-Access1 P 192.168.255.252/30, 1 successors, FD is 28160 via Connected, Vlan87 P 15.73.18.11/32, 1 successors, FD is 27008000 via 172.16.168.2 (27008000/128256), Virtual-Access1
CE-Cisco_2911HUB#ping 172.16.168.2 Type escape sequence to abort. Sending 5, 100-byte ICMP Echos to 172.16.168.2, timeout is 2 seconds: ..... Success rate is 0 percent (0/5)
Solved! Go to Solution.
06-25-2018 09:48 AM - edited 06-25-2018 09:55 AM
Have you defined the subnet mask of the loopback interfaces used for the tunnel as a /28 on both routers? Change it to a /32 on both routers then check your routing table again
06-25-2018 08:22 AM
06-25-2018 08:26 AM
06-25-2018 09:48 AM - edited 06-25-2018 09:55 AM
Have you defined the subnet mask of the loopback interfaces used for the tunnel as a /28 on both routers? Change it to a /32 on both routers then check your routing table again
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide