cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
839
Views
0
Helpful
4
Replies

Issues while using mGRE and p2p GRE tunnel with vpn spa on 6500

jbest1028
Level 1
Level 1

Have a 6500 using the vpn spa with ipsec tunnels. The plan is to migrate all tunnels over to DMVPN. When we configured the mGRE tunnel and bring it up, all the other tunnels slowly drop. As soon as we shutdown the mGRE tunnel, all other tunnels come up. We have a tunnel key set for the mGRE tunnel. The only limitations I could find were that we only source 1 mGRE tunnel from an interface, I could not find anything about sharing and interface with p3p tunnels. Anyone know if it is possible to source an mGRE tunnel and p3p tunnel from the same interface?

4 Replies 4

Ivan Martinon
Level 7
Level 7

If you are going to use the same shared interface for both mgre and p2p GRE tunnels you need to use the "shared" on the tunnel protection command keyword on all the tunnels.

Interface tunnel XXXX

tunnel protection ipsec profile ZZZZZ shared

Don't think that is supported on the 6500, that command was introduced in 12.4.15T.

You got me in there, apologies for that, I have been researching about this and it seems there is no way around for this and instead you need to define separate interfaces.

ijalba_cisco
Level 1
Level 1

Same issue here. How you solved this?

Thanks