cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
373
Views
2
Helpful
2
Replies

IPsec Tunnel Interface Won’t Come Up

CHISHIUNG
Spotlight
Spotlight

I am trying to use a tunnel interface with route-based IPsec.
However, the following log message is being output, and the tunnel interface keeps switching between the "up" and "down" states. Could you please advise me on the cause of this issue?
The remote side is using policy-based IPsec. Does the remote side also need to switch to route-based IPsec?

*Aug 30 07:54:14.194: %ADJ-5-PARENT: Midchain parent maintenance for IP midchain out of Tunnel1 - looped chain attempting to stack
*Aug 30 07:54:18.215: %TUN-5-RECURDOWN: Tunnel1 temporarily disabled due to recursive routing
*Aug 30 07:54:18.215: %LINEPROTO-5-UPDOWN: Line protocol on Interface Tunnel1 changed state to down

1 Accepted Solution

Accepted Solutions

@CHISHIUNG 

What routing have you configured? As "Tunnel1 temporarily disabled due to recursive routing" indicates a routing problem.

A route based VPN will have traffic selectors of 0.0.0.0/0.0.0.0 if the peer is using a policy based VPN, then the traffic selectors will be whatever they define in their crypto ACL, which I assume does not mirror yours and thus causing a mis-match. 

You and the peer should align and both use the same, either route based or policy based.

On IOS-XE, you can implement Multi SA on your side and mirror the peers traffic selectors https://www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/214728-configure-multi-sa-virtual-tunnel-interf.html - Multi SA is a hybrid route/policy based VPN solution.

View solution in original post

2 Replies 2

@CHISHIUNG 

What routing have you configured? As "Tunnel1 temporarily disabled due to recursive routing" indicates a routing problem.

A route based VPN will have traffic selectors of 0.0.0.0/0.0.0.0 if the peer is using a policy based VPN, then the traffic selectors will be whatever they define in their crypto ACL, which I assume does not mirror yours and thus causing a mis-match. 

You and the peer should align and both use the same, either route based or policy based.

On IOS-XE, you can implement Multi SA on your side and mirror the peers traffic selectors https://www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/214728-configure-multi-sa-virtual-tunnel-interf.html - Multi SA is a hybrid route/policy based VPN solution.

@Rob Ingram 

After changing the VPN router on the other end to route-based mode and configuring a static route to the site's LAN segment with the tunnel interface as the destination, the tunnel interface came up!