08-15-2018 08:48 PM - edited 02-21-2020 09:26 PM
I have a very strange issue that I can't explain that I was hoping for fresh ideas.
Scenario - We have 100 spokes, all have 881's with dual DMVPN tunnels to two different Data Centers. The DMVPN hub routers site behind ASA's.
Issue - One of the spokes (let's call it site 83) can not ping the DMVPN hub tunnel IP.
Troubleshooting done -
Question - At this point it seems pretty clear that the issue lies with the ISP cable modem but I can't explain how/why something is able to filter out only the ENCRYPTED ICMP packets yet other encrypted packets have no issue reaching the destination. Any ideas guys?
Solved! Go to Solution.
08-17-2018 08:28 AM
*UPDATE*
As expected after the ISP replaced the modem the issue is now resolved. This is concerning because somehow the 'faulty' modem was able to differentiate between IPsec encrypted ICMP packets and other IPsec encrypted traffic. Big brother or some other malicious agent on the modem?
08-16-2018 12:04 AM
08-16-2018 05:39 AM
Mohammed,
Yes I've done a ping sweep starting with 36 byte all the way to 1360.
08-16-2018 10:23 AM
08-17-2018 05:49 AM - edited 08-17-2018 05:50 AM
Mohammed,
The output of 'show ip route x.x.x.x' and 'show ip cef x.x.x.x' are what would be expected (the tunnel interface and hub tunnel IP.) The output of 'show ip nhrp brief' shows the correct mapping. Regarding the traceroute, keep in mind that the packets are leaving the Cisco router properly as I verified via packet capture so there's no issue on that device.
08-17-2018 08:28 AM
*UPDATE*
As expected after the ISP replaced the modem the issue is now resolved. This is concerning because somehow the 'faulty' modem was able to differentiate between IPsec encrypted ICMP packets and other IPsec encrypted traffic. Big brother or some other malicious agent on the modem?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide