08-30-2026 02:32 AM
I am trying to use a tunnel interface with route-based IPsec.
However, the following log message is being output, and the tunnel interface keeps switching between the "up" and "down" states. Could you please advise me on the cause of this issue?
The remote side is using policy-based IPsec. Does the remote side also need to switch to route-based IPsec?
*Aug 30 07:54:14.194: %ADJ-5-PARENT: Midchain parent maintenance for IP midchain out of Tunnel1 - looped chain attempting to stack
*Aug 30 07:54:18.215: %TUN-5-RECURDOWN: Tunnel1 temporarily disabled due to recursive routing
*Aug 30 07:54:18.215: %LINEPROTO-5-UPDOWN: Line protocol on Interface Tunnel1 changed state to down
Solved! Go to Solution.
08-30-2026 02:39 AM
What routing have you configured? As "Tunnel1 temporarily disabled due to recursive routing" indicates a routing problem.
A route based VPN will have traffic selectors of 0.0.0.0/0.0.0.0 if the peer is using a policy based VPN, then the traffic selectors will be whatever they define in their crypto ACL, which I assume does not mirror yours and thus causing a mis-match.
You and the peer should align and both use the same, either route based or policy based.
On IOS-XE, you can implement Multi SA on your side and mirror the peers traffic selectors https://www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/214728-configure-multi-sa-virtual-tunnel-interf.html - Multi SA is a hybrid route/policy based VPN solution.
08-30-2026 02:39 AM
What routing have you configured? As "Tunnel1 temporarily disabled due to recursive routing" indicates a routing problem.
A route based VPN will have traffic selectors of 0.0.0.0/0.0.0.0 if the peer is using a policy based VPN, then the traffic selectors will be whatever they define in their crypto ACL, which I assume does not mirror yours and thus causing a mis-match.
You and the peer should align and both use the same, either route based or policy based.
On IOS-XE, you can implement Multi SA on your side and mirror the peers traffic selectors https://www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/214728-configure-multi-sa-virtual-tunnel-interf.html - Multi SA is a hybrid route/policy based VPN solution.
08-30-2026 06:42 AM
After changing the VPN router on the other end to route-based mode and configuring a static route to the site's LAN segment with the tunnel interface as the destination, the tunnel interface came up!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide