cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1029
Views
0
Helpful
1
Replies

ISM-VPN-39 breaks High Availality GRE IPSec

net.comm.engr
Level 1
Level 1

Hello everyone,

Just wonder if anyone have any experience configuring ism-vpn-39 with gre over ipsec using HSRP virtual IP as the tunnel source and destination endpoints? My configuration is working perfectly fine if I disable ism-vpn-39 with "no crypto slot 0". But as soon as I re-enable this accelerator, all the tunnels drop. I'm using the latest IOS 15.3-2T.

I've also been having headache with this module and older IOS versions, it either crashes the router or strangely breaks the traffic between the router and the installed switch service module (SM-ES3G-24-P) after about 3 hours of operation. The fix was to upgrade to the latest IOS but then it causes the probem above. Thanks for insight.

1 Reply 1

Tarik Admani
VIP Alumni
VIP Alumni

Hi,

There seems to a few bugs that are resolved in the latest 15.3-2T but seem to still have the same symptoms that you are experiencing. Crashing of the module when icmpv6 pings are issued to the router, the ism-vpn not encapsulating esp packets..etc. You may need to open a tac case to validate that this bugs are fixed and are in a verfied or resolved state.

Here is a link to the release notes and there are quite a few bugs related to the ism-vpn module.

http://www.cisco.com/en/US/docs/ios/15_3m_and_t/release/notes/153-2TCAVS.html#wp56114

Tarik Admani
*Please rate helpful posts*