cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4679
Views
0
Helpful
10
Replies

2911 w/4G - Connection going up and down

jeffrey-archer
Level 1
Level 1

I am setting up a 2911 router with both AT&T and Verizon 4G LTE Service. The AT&T services is working like a charm, but the Verizon services keeps bouncing up and down. As soon as I try to send traffic over the Verizon it will drop the connection, and then reestablish the connection and then repeat again. I have shutdown cellular 0/1/0 so there would be on conflict, but it doesn't help. I have been searching for days with no resolution. Any help would be greatly appreciated.

Thanks......Jeff

Below is my config.

>>>>>>>>>>>>>>>>>>>>

version 15.5
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
!
hostname 2911_Router
!
boot-start-marker
boot system flash:c2900-universalk9-mz.SPA.155-3.M7.bin
boot-end-marker
!
!
logging buffered 100000
no logging monitor
!
aaa new-model
!
ethernet lmi global
ethernet lmi ce
!
no ip source-route
!!
ip vrf COVA-(Host)
 rd 2:126
 route-target export 2:126
 route-target import 2:126
!
no ip bootp server
no ip domain lookup
ip name-server 10.192.40.50
ip name-server 10.208.40.50
ip cef
no ipv6 cef
!
multilink bundle-name authenticated
!
!
!
chat-script lte "" "AT!CALL" TIMEOUT 60 "OK"
!
crypto pki trustpoint (Host Name)
 enrollment retry count 3
 enrollment retry period 5
 enrollment url http://10.192.6.97:80
 serial-number
 vrf COVA-(Host)
 revocation-check none
 source interface Loopback1226
 auto-enroll 70
 authorization username subjectname all
!
crypto pki trustpoint (Host Name)
 enrollment retry count 3
 enrollment retry period 5
 enrollment url http://10.208.6.97:80
 serial-number
 vrf COVA-(Host)
 revocation-check none
 source interface Loopback1226
 auto-enroll 70
 authorization username subjectname all
!
!
redundancy
!
controller Cellular 0/1
 lte modem link-recovery rssi onset-threshold -110
 lte modem link-recovery monitor-timer 20
 lte modem link-recovery wait-timer 10
 lte modem link-recovery debounce-count 6
!
controller Cellular 0/2
 lte modem link-recovery rssi onset-threshold -110
 lte modem link-recovery monitor-timer 20
 lte modem link-recovery wait-timer 10
 lte modem link-recovery debounce-count 6
!
!
!
crypto isakmp policy 1
 encr aes 256
 authentication pre-share
 lifetime 14400
!
crypto isakmp policy 2
 encr aes 256
 authentication pre-share
!
crypto isakmp policy 5
 encr aes 256
 group 14
 lifetime 14400
crypto isakmp key COVA-TEST address (Public IP)
crypto isakmp key COVAercs@1 address 0.0.0.0
crypto isakmp invalid-spi-recovery
crypto isakmp keepalive 45 27
!
crypto ipsec security-association idle-time 600
!
crypto ipsec transform-set COVA-VPN esp-aes 256 esp-sha-hmac
 mode transport
!
crypto ipsec profile DMVPN
 set security-association lifetime seconds 43200
 set transform-set COVA-VPN
!
!
!
crypto call admission limit ike in-negotiation-sa 20
!
interface Loopback1226
 ip vrf forwarding COVA-(Host)
 ip address 10.156.0.96 255.255.255.255
!
interface Tunnel1226
 description *** AT&T mGRE Tunnel  ***
 ip vrf forwarding COVA-(Host)
 ip address 10.156.2.7 255.255.255.128
 no ip redirects
 no ip proxy-arp
 ip mtu 1400
 ip hello-interval eigrp 226 40
 ip hold-time eigrp 226 120
 ip nhrp authentication COV-ERCS
 ip nhrp map 10.156.2.1 (Public IP)
 ip nhrp map multicast (Public IP)
 ip nhrp network-id 1226
 ip nhrp holdtime 600
 ip nhrp nhs 10.156.2.1
 ip nhrp registration timeout 75
 ip nhrp shortcut
 ip summary-address eigrp 226 10.157.206.0 255.255.255.0
 ip tcp adjust-mss 1360
 qos pre-classify
 tunnel source Cellular0/1/0
 tunnel mode gre multipoint
 tunnel key 1226
 tunnel protection ipsec profile DMVPN
!
interface Tunnel2226
 description *** Verizon mGRE Tunnel  ***
 ip vrf forwarding COVA-(Host)
 ip address 10.156.2.135 255.255.255.128
 no ip redirects
 no ip proxy-arp
 ip mtu 1400
 ip hello-interval eigrp 226 40
 ip hold-time eigrp 226 120
 ip nhrp authentication COV-ERCS
 ip nhrp map multicast (Public IP)
 ip nhrp map 10.156.2.129 (Public IP)
 ip nhrp network-id 2226
 ip nhrp holdtime 600
 ip nhrp nhs 10.156.2.129
 ip nhrp registration timeout 75
 ip nhrp shortcut
 ip summary-address eigrp 226 10.157.206.0 255.255.255.0
 ip tcp adjust-mss 1360
 delay 1000000
 qos pre-classify
 tunnel source Cellular0/2/0
 tunnel mode gre multipoint
 tunnel key 2226
 tunnel protection ipsec profile DMVPN
!
interface Embedded-Service-Engine0/0
 no ip address
 shutdown
!
interface GigabitEthernet0/0
 no ip address
 shutdown
 duplex auto
 speed auto
!
interface GigabitEthernet0/0.5
 description Trusted
 encapsulation dot1Q 5
 ip vrf forwarding COVA-(Host)
 ip address 10.157.206.1 255.255.255.192
 no cdp enable
!
interface GigabitEthernet0/0.6
 description Servers
 encapsulation dot1Q 6
 ip vrf forwarding COVA-(Host)
 ip address 10.157.206.129 255.255.255.192
 no cdp enable
!
interface GigabitEthernet0/0.126
 description Management_VLAN
 encapsulation dot1Q 126
 ip vrf forwarding   COVA-(Host)
 ip address 10.157.206.217 255.255.255.248
 no cdp enable
!
interface GigabitEthernet0/1
 ip address dhcp
 shutdown
 duplex auto
 speed auto
!
interface GigabitEthernet0/2
 ip address dhcp
 shutdown
 duplex auto
 speed auto
!
interface Cellular0/1/0

  description AT&T 4G LTE Service
 ip address negotiated previous
 ip virtual-reassembly in
 encapsulation slip
 dialer in-band
 dialer string lte
 dialer-group 1
 async mode interactive
!
interface Cellular0/2/0

  description Verizon 4G LTE Service
 mtu 1400
 ip address negotiated previous
 ip virtual-reassembly in
 encapsulation slip
 dialer in-band
 dialer string lte
 dialer-group 1
 async mode interactive
!
interface Cellular0/1/1
 no ip address
 encapsulation slip
!
!
!
router eigrp 1
 !
 address-family ipv4 vrf COVA-(Host)
  network 10.156.0.96 0.0.0.0
  network 10.156.2.0 0.0.0.255
  network 10.157.206.0 0.0.0.255
  autonomous-system 226
  eigrp stub connected summary
 exit-address-family
!
ip forward-protocol nd
!
no ip http server
ip http access-class 23
ip http authentication local
no ip http secure-server
ip http timeout-policy idle 60 life 86400 requests 10000
!
ip route 0.0.0.0 0.0.0.0 Cellular0/2/0
ip route 0.0.0.0 0.0.0.0 Cellular0/1/0
ip ssh version 2
!
dialer-list 1 protocol ip list 4
!

access-list 4 permit any

!
snmp-server community private RW
snmp-server community public RO
snmp-server community aelGema3 RO 1
snmp-server trap-source Loopback1226
snmp-server enable traps snmp linkdown linkup
snmp-server enable traps tty
snmp-server enable traps c3g
snmp-server host 10.192.32.15 version 2c aelGema3
snmp-server host 10.156.0.96 vrf COVA-(Host) private
snmp-server host 10.157.206.2 vrf COVA-(Host) private
snmp-server host 10.194.5.22 vrf COVA-(Host)private
snmp-server manager
snmp mib notification-log default
!
control-plane
!
 vstack
!
line con 0
 logging synchronous
line aux 0
line 2
 no activation-character
 no exec
 transport preferred none
 transport output lat pad telnet rlogin lapb-ta mop udptn v120 ssh
 stopbits 1
line 0/1/0
 script dialer lte
 no exec
 transport preferred none
 transport output none
 rxspeed 100000000
 txspeed 50000000
line 0/1/1
 no exec
 rxspeed 100000000
 txspeed 50000000
line 0/2/0
 script dialer lte
 modem InOut
 no exec
 rxspeed 100000000
 txspeed 50000000
line vty 0 4
 access-class VTY_Control in vrf-also
 privilege level 15
 transport input telnet ssh
!
scheduler allocate 20000 1000
ntp broadcastdelay 80
ntp update-calendar
ntp server vrf COVA-(Host) 10.193.242.97 prefer

1 Accepted Solution

Accepted Solutions

George, Thank You Very Much.  Your configuration seems to have corrected the issue and my Verizon connection is staying up. Thank you also for the explanation as to why it was happening. Now I just need to figure out how to get the Event Manager script to work with the new cards. I'll start a new thread for that.

 

Thank You again......Jeff 

View solution in original post

10 Replies 10

Hi Jeff,

 

Please correct the MTU on the Verizon mGRE Tunnel or interface Cell0/2/0:

 

interface Tunnel2226
 description *** Verizon mGRE Tunnel  ***
 ip vrf forwarding COVA-(Host)
 ip address 10.156.2.135 255.255.255.128
 no ip redirects
 no ip proxy-arp
 ip mtu 1300
 ip hello-interval eigrp 226 40
 ip hold-time eigrp 226 120
 ip nhrp authentication COV-ERCS
 ip nhrp map multicast (Public IP)
 ip nhrp map 10.156.2.129 (Public IP)
 ip nhrp network-id 2226
 ip nhrp holdtime 600
 ip nhrp nhs 10.156.2.129
 ip nhrp registration timeout 75
 ip nhrp shortcut
 ip summary-address eigrp 226 10.157.206.0 255.255.255.0
 ip tcp adjust-mss 1260
 delay 1000000
 qos pre-classify
 tunnel source Cellular0/2/0
 tunnel mode gre multipoint
 tunnel key 2226
 tunnel protection ipsec profile DMVPN
!

!
interface Cellular0/2/0

  description Verizon 4G LTE Service
 mtu 1400 (Or change it to  mtu 1500 unless you have specific reason)
 ip address negotiated previous
 ip virtual-reassembly in
 encapsulation slip
 dialer in-band
 dialer string lte
 dialer-group 1
 async mode interactive

!

 

Please do not forget to rate correct answers.

 

HTH,

Meheretab

HTH,
Meheretab

Thank you Meheretab, that was left over as part of troubleshooting. It made no difference nor did I think it would. The Interface continues to go down and then comes back up. I just can't seem to figure it out. Here are some of the debugs I'm getting.

 

Aug  6 21:45:49.702: cellwan_api_pkt_session_notify: instance id:0 profile:2 status:0
.Aug  6 21:45:49.702: %CELLWAN-2-BEARER_DELETED: Instance id=0, Default bearer (bearer_id=6) in Cellular0/2/0 is now deleted.
.Aug  6 21:45:49.702: Pdn 0: clear profile id 3
.Aug  6 21:45:49.702: Cellular0/2/0 profile 2, session INACTIVE
.Aug  6 21:45:49.702: !!! 4G/LTE modem CARDROP!!!!
.Aug  6 21:45:49.702: ttynum:35: new DSR value received, 1

.Aug  6 21:45:49.702: old value: handshakes->DSR= 1

.Aug  6 21:
DMV-096-R1#45:49.702: new DCD value received, 0

.Aug  6 21:45:49.702: old value: handshakes->DCD= 0

.Aug  6 21:45:49.702: Cellular0/2/0 DirectIP: Remove negotiated IP interface address
.Aug  6 21:45:49.702: %LINEPROTO-5-UPDOWN: Line protocol on Interface Tunnel2226, changed state to down
.Aug  6 21:45:49.702: Cellular0/2/0 DirectIP: Primary DNS address 198.224.137.129 removed
.Aug  6 21:45:49.702: Cellular0/2/0 DirectIP: Primary DNS address 2001:4888:1B:FF00:1D1:D:: removed
.Aug  6 21:45:49.702: Cellular0/2
DMV-096-R1#/0 DirectIP: Secondary DNS address 198.224.138.129 removed
.Aug  6 21:45:49.702: Cellular0/2/0 DirectIP: Secondary DNS address 2001:4888:1A:FF00:1D2:D:: removed
.Aug  6 21:45:49.758: cellwan_api_pkt_session_notify: instance id:0 profile:2 status:0
.Aug  6 21:45:49.758: %CELLWAN-2-BEARER_DELETED: Instance id=0, Default bearer (bearer_id=255) in Cellular0/2/0 is now deleted.
.Aug  6 21:45:49.758: cellular_update_profile_id_for_latest_call_setup: pending_idb:0x3F254358
.Aug  6 21:45:49.758: LSI DIP call
DMV-096-R1#set-up failure for Cellular0/2/0: profile_id = 3, active_status = 0, pdp_ctxt = 0
.Aug  6 21:45:49.758: Cellular0/2/0 profile 2, session INACTIVE
.Aug  6 21:45:49.758: !!! 4G/LTE modem CARDROP!!!!
.Aug  6 21:45:49.758: ttynum:35: new DSR value received, 1

.Aug  6 21:45:49.758: old value: handshakes->DSR= 1

.Aug  6 21:45:49.758: new DCD value received, 0

.Aug  6 21:45:49.758: old value: handshakes->DCD= 0

.Aug  6 21:45:49.758: Cellular0/2/0 DirectIP: Remove negotiated IP interface address
.A
DMV-096-R1#ug  6 21:45:51.702: %LINK-5-CHANGED: Interface Cellular0/2/0, changed state to reset
.Aug  6 21:45:52.702: %LINEPROTO-5-UPDOWN: Line protocol on Interface Cellular0/2/0, changed state to down
DMV-096-R1#
.Aug  6 21:45:56.702: %LINK-3-UPDOWN: Interface Cellular0/2/0, changed state to down
DMV-096-R1#
.Aug  6 21:46:30.166: cellwan_api_pkt_session_notify: instance id:0 profile:2 status:1
.Aug  6 21:46:30.166: %CELLWAN-2-BEARER_UP: Instance id=0, Default bearer (bearer_id=6) in Cellular0/2/0 is now UP
DMV-096-R1#
.Aug  6 21:46:30.166: cellular_update_profile_id_for_latest_call_setup: pending_idb:0x3F254358
.Aug  6 21:46:30.166: Pdn 0: set profile id 3
.Aug  6 21:46:30.166: Cellular0/2/0 profile 2, session ACTIVE
.Aug  6 21:46:30.166: cellwan_api_pkt_session_notify:connected idb_subunit:0
.Aug  6 21:46:30.358: cellwan_api_pkt_session_notify: instance id:0 profile:2 status:1
.Aug  6 21:46:30.358: %CELLWAN-2-BEARER_UP: Instance id=0, Default bearer (bearer_id=6) in Cellular0/2/0 is now UP
DMV-096-R1#
.Aug  6 21:46:30.358: handle_call_history: new and old status the same 1
.Aug  6 21:46:30.358: Cellular0/2/0 profile 2, session ACTIVE
.Aug  6 21:46:30.358: cellwan_api_pkt_session_notify:connected idb_subunit:0
DMV-096-R1#
.Aug  6 21:46:32.754:  cellwan_api_handle_profile_ip_addr_get_resp pdn 0 valid 1 length 4 session active 1, profile:2

.Aug  6 21:46:32.754:   IPV6 Address = 2600:1003:B45E:C164:870:44FF:FEBA:108/64
  Scope: Global
.Aug  6 21:46:32.758:   IPV6 Address = FE80:0:0:0:870:44FF:FEBA:108/64
  Scope: Link
.Aug  6 21:46:32.758: Sending ok response to line:35
.Aug  6 21:46:32.758: ttynum:35: new DSR value received, 1

.Aug  6 21:46:32.758: old value: handshakes->DSR= 1

.Aug  6 21:46:32.758: new DCD valu
DMV-096-R1#e received, 1

.Aug  6 21:46:32.758: old value: handshakes->DCD= 1

.Aug  6 21:46:33.234: Cellular0/2/0 DirectIP: Primary DNS address 198.224.137.129 added
.Aug  6 21:46:33.234: Cellular0/2/0 DirectIP: Primary IPV6 DNS address 2001:4888:1B:FF00:1D1:D:: added
.Aug  6 21:46:33.234: Cellular0/2/0 DirectIP: Secondary DNS 198.224.138.129 added
.Aug  6 21:46:33.234: Cellular0/2/0 DirectIP: Secondary IPV6 DNS 2001:4888:1A:FF00:1D2:D:: added
.Aug  6 21:46:33.498:  cellwan_api_handle_profile_ip_addr_get_res
DMV-096-R1#p pdn 0 valid 1 length 4 session active 1, profile:2

.Aug  6 21:46:33.498:   IPV6 Address = 2600:1003:B45E:C164:870:44FF:FEBA:108/64
  Scope: Global
.Aug  6 21:46:33.498: Sending ok response to line:35
.Aug  6 21:46:33.498: ttynum:35: new DSR value received, 1

.Aug  6 21:46:33.498: old value: handshakes->DSR= 1

.Aug  6 21:46:33.498: new DCD value received, 1

.Aug  6 21:46:33.498: old value: handshakes->DCD= 1

.Aug  6 21:46:33.682: Cellular0/2/0 DirectIP: Primary DNS address 198.224.137.129
DMV-096-R1# added
.Aug  6 21:46:33.682: Cellular0/2/0 DirectIP: Primary IPV6 DNS address 2001:4888:1B:FF00:1D1:D:: added
.Aug  6 21:46:33.682: Cellular0/2/0 DirectIP: Secondary DNS 198.224.138.129 added
.Aug  6 21:46:33.682: Cellular0/2/0 DirectIP: Secondary IPV6 DNS 2001:4888:1A:FF00:1D2:D:: added
.Aug  6 21:46:34.758: %LINK-3-UPDOWN: Interface Cellular0/2/0, changed state to up
.Aug  6 21:46:34.758: Cellular0/2/0 DirectIP: Install negotiated IP interface address 100.120.48.90
.Aug  6 21:46:34.758: %LINEPROTO-
DMV-096-R1#5-UPDOWN: Line protocol on Interface Tunnel2226, changed state to up
.Aug  6 21:46:34.762: %CRYPTO-6-ISAKMP_ON_OFF: ISAKMP is OFF
.Aug  6 21:46:34.762: %CRYPTO-6-ISAKMP_ON_OFF: ISAKMP is ON
.Aug  6 21:46:35.758: %LINEPROTO-5-UPDOWN: Line protocol on Interface Cellular0/2/0, changed state to up

  

 

Hello,

 

can you post the output of:

 

show cell 0/2 radio

show cell 0/2 network

Yes Sir.

 

show cellular 0/2/0 radio
Radio power mode = online
LTE Rx Channel Number =  2150
LTE Tx Channel Number =  20150
LTE Band =  4
LTE Bandwidth = 20 MHz
Current RSSI = -70 dBm
Current RSRP = -99 dBm
Current RSRQ = -10 dB
Current SNR = 9.6  dB
Physical Cell Id = 168
Number of nearby cells = 1
Idx      PCI (Physical Cell Id)
--------------------------------
1              168
Radio Access Technology(RAT) Preference = AUTO
Radio Access Technology(RAT) Selected = LTE

>>>>>>>>>>>>>>>>>

show cellular 0/2/0 network
Current System Time = Tue Aug 7 13:44:14 2018
Current Service Status = Normal
Current Service = Packet switched
Current Roaming Status = Home
Network Selection Mode = Automatic
Network = VzW
Mobile Country Code (MCC) = 311
Mobile Network Code (MNC) = 480
Packet switch domain(PS) state = Attached
Registration state(EMM) = Registered
EMM Sub State = Normal Service
Tracking Area Code (TAC) = 29185
Cell ID = 29287436

 

Hello,

 

the values look good. What about the output of:

 

show cell 0/2/0 profile ?

 

Profile 3 is I think the default data profile for Verizon, make sure it is configured...

Here is the Profile for Cellular 0/2/0 along with the Hardware

Profile 3 = ACTIVE*
--------
PDP Type = IPv4v6
PDP address = 100.108.199.73
PDP IPV6 address = 2600:1003:B456:5605:870:44FF:FEBA:108/64  Scope: Global
Access Point Name (APN) = VZWINTERNET
Authentication = None
        Primary DNS address = 198.224.137.129
        Secondary DNS address = 198.224.138.129
        Primary DNS IPV6 address = 2001:4888:1B:FF00:1D1:D:0:0
        Secondary DNS IPV6 address = 2001:4888:1A:FF00:1D2:D:0:0

>>>>>>>>>>>>>>>>>

show cellular 0/2/0 hardware
Modem Firmware Version = SWI9X15C_05.05.58.01
Modem Firmware built = 2015/03/05 00:02:40
Hardware Version = 1.0
Device Model ID: MC7350
Package Identifier ID: 1102036_9903208_MC7350_05.05.58.01_00_Cisco_005.007_000
International Mobile Subscriber Identity (IMSI) = 311480423457025
International Mobile Equipment Identity (IMEI) = 356732060775168
Integrated Circuit Card ID (ICCID) = 89148000004199047427
Mobile Subscriber Integrated Services
Digital Network-Number (MSISDN) = 8045131608
Current Modem Temperature = 34 deg C
PRI SKU ID = 1102036, PRI version = 005.029, Carrier = Verizon
OEM PRI version = 05.07

Hello,

 

Verizon requires ALL traffic leaving the LTE to have as the source the IP address being that of the LTE interface:

 

--> If any packets are sent over LTE with the source IP address other than the LTE interface IP address, the LTE connection will be disconnected (because of an IP address violation). Because the router will immediately attempt to reconnect, a flapping condition will occur and continue <--

 

I have added NAT to the Verizon side of your config, give that a try (I leave the AT&T side alone since that is working fine).

 

Verizon also recommends to configure a route map to clear the DF bits (also added).

 

All changes are marked in bold:

 

 

hostname 2911_Router
!
boot-start-marker
boot system flash:c2900-universalk9-mz.SPA.155-3.M7.bin
boot-end-marker
!
!
logging buffered 100000
no logging monitor
!
aaa new-model
!
ethernet lmi global
ethernet lmi ce
!
no ip source-route
!!
ip vrf COVA-(Host)
rd 2:126
route-target export 2:126
route-target import 2:126
!
no ip bootp server
no ip domain lookup
ip name-server 10.192.40.50
ip name-server 10.208.40.50
ip cef
no ipv6 cef
!
multilink bundle-name authenticated
!
!
!
chat-script lte "" "AT!CALL" TIMEOUT 60 "OK"
!
crypto pki trustpoint (Host Name)
enrollment retry count 3
enrollment retry period 5
enrollment url http://10.192.6.97:80
serial-number
vrf COVA-(Host)
revocation-check none
source interface Loopback1226
auto-enroll 70
authorization username subjectname all
!
crypto pki trustpoint (Host Name)
enrollment retry count 3
enrollment retry period 5
enrollment url http://10.208.6.97:80
serial-number
vrf COVA-(Host)
revocation-check none
source interface Loopback1226
auto-enroll 70
authorization username subjectname all
!
!
redundancy
!
controller Cellular 0/1
lte modem link-recovery rssi onset-threshold -110
lte modem link-recovery monitor-timer 20
lte modem link-recovery wait-timer 10
lte modem link-recovery debounce-count 6
!
controller Cellular 0/2
lte modem link-recovery rssi onset-threshold -110
lte modem link-recovery monitor-timer 20
lte modem link-recovery wait-timer 10
lte modem link-recovery debounce-count 6
!
!
!
crypto isakmp policy 1
encr aes 256
authentication pre-share
lifetime 14400
!
crypto isakmp policy 2
encr aes 256
authentication pre-share
!
crypto isakmp policy 5
encr aes 256
group 14
lifetime 14400
crypto isakmp key COVA-TEST address (Public IP)
crypto isakmp key COVAercs@1 address 0.0.0.0
crypto isakmp invalid-spi-recovery
crypto isakmp keepalive 45 27
!
crypto ipsec security-association idle-time 600
!
crypto ipsec transform-set COVA-VPN esp-aes 256 esp-sha-hmac
mode transport
!
crypto ipsec profile DMVPN
set security-association lifetime seconds 43200
set transform-set COVA-VPN
!
!
!
crypto call admission limit ike in-negotiation-sa 20
!
interface Loopback1226
ip vrf forwarding COVA-(Host)
ip address 10.156.0.96 255.255.255.255
!
interface Tunnel1226
description *** AT&T mGRE Tunnel ***
ip vrf forwarding COVA-(Host)
ip address 10.156.2.7 255.255.255.128
no ip redirects
no ip proxy-arp
ip mtu 1400
ip hello-interval eigrp 226 40
ip hold-time eigrp 226 120
ip nhrp authentication COV-ERCS
ip nhrp map 10.156.2.1 (Public IP)
ip nhrp map multicast (Public IP)
ip nhrp network-id 1226
ip nhrp holdtime 600
ip nhrp nhs 10.156.2.1
ip nhrp registration timeout 75
ip nhrp shortcut
ip summary-address eigrp 226 10.157.206.0 255.255.255.0
ip tcp adjust-mss 1360
qos pre-classify
tunnel source Cellular0/1/0
tunnel mode gre multipoint
tunnel key 1226
tunnel protection ipsec profile DMVPN
!
interface Tunnel2226
description *** Verizon mGRE Tunnel ***
ip vrf forwarding COVA-(Host)
ip address 10.156.2.135 255.255.255.128
no ip redirects
no ip proxy-arp
ip mtu 1400
ip hello-interval eigrp 226 40
ip hold-time eigrp 226 120
ip policy route-map clear-df
ip nhrp authentication COV-ERCS
ip nhrp map multicast (Public IP)
ip nhrp map 10.156.2.129 (Public IP)
ip nhrp network-id 2226
ip nhrp holdtime 600
ip nhrp nhs 10.156.2.129
ip nhrp registration timeout 75
ip nhrp shortcut
ip summary-address eigrp 226 10.157.206.0 255.255.255.0
ip tcp adjust-mss 1300
delay 1000000
qos pre-classify
tunnel source Cellular0/2/0
tunnel mode gre multipoint
tunnel key 2226
tunnel protection ipsec profile DMVPN
!
interface Embedded-Service-Engine0/0
no ip address
shutdown
!
interface GigabitEthernet0/0
no ip address
shutdown
duplex auto
speed auto
!
interface GigabitEthernet0/0.5
description Trusted
encapsulation dot1Q 5
ip vrf forwarding COVA-(Host)
ip address 10.157.206.1 255.255.255.192

ip nat inside
ip tcp adjust-mss 1300
ip policy route-map clear-df
no cdp enable
!
interface GigabitEthernet0/0.6
description Servers
encapsulation dot1Q 6
ip vrf forwarding COVA-(Host)
ip address 10.157.206.129 255.255.255.192

ip nat inside
ip tcp adjust-mss 1300
ip policy route-map clear-df
no cdp enable
!
interface GigabitEthernet0/0.126
description Management_VLAN
encapsulation dot1Q 126
ip vrf forwarding COVA-(Host)
ip address 10.157.206.217 255.255.255.248

ip nat inside
ip tcp adjust-mss 1300
ip policy route-map clear-df
no cdp enable
!
interface GigabitEthernet0/1
ip address dhcp
shutdown
duplex auto
speed auto
!
interface GigabitEthernet0/2
ip address dhcp
shutdown
duplex auto
speed auto
!
interface Cellular0/1/0

description AT&T 4G LTE Service
ip address negotiated previous
ip virtual-reassembly in
encapsulation slip
dialer in-band
dialer string lte
dialer-group 1
async mode interactive
!
interface Cellular0/2/0

description Verizon 4G LTE Service
mtu 1400
ip address negotiated previous

ip nat outside
ip virtual-reassembly in
encapsulation slip
dialer in-band
dialer string lte
dialer-group 1
async mode interactive
!
interface Cellular0/1/1
no ip address
encapsulation slip
!
!
!
router eigrp 1
!
address-family ipv4 vrf COVA-(Host)
network 10.156.0.96 0.0.0.0
network 10.156.2.0 0.0.0.255
network 10.157.206.0 0.0.0.255
autonomous-system 226
eigrp stub connected summary
exit-address-family
!
ip forward-protocol nd
!
no ip http server
ip http access-class 23
ip http authentication local
no ip http secure-server
ip http timeout-policy idle 60 life 86400 requests 10000
!
ip nat inside source list 100 interface Cellular0/2/0 overload
ip route 0.0.0.0 0.0.0.0 Cellular0/2/0
ip route 0.0.0.0 0.0.0.0 Cellular0/1/0
ip ssh version 2
!
dialer-list 1 protocol ip list 4
!
access-list 100 permit ip any any
!
access-list 4 permit any
!
route-map clear-df permit 10
set ip df 0
!
snmp-server community private RW
snmp-server community public RO
snmp-server community aelGema3 RO 1
snmp-server trap-source Loopback1226
snmp-server enable traps snmp linkdown linkup
snmp-server enable traps tty
snmp-server enable traps c3g
snmp-server host 10.192.32.15 version 2c aelGema3
snmp-server host 10.156.0.96 vrf COVA-(Host) private
snmp-server host 10.157.206.2 vrf COVA-(Host) private
snmp-server host 10.194.5.22 vrf COVA-(Host)private
snmp-server manager
snmp mib notification-log default
!
control-plane
!
vstack
!
line con 0
logging synchronous
line aux 0
line 2
no activation-character
no exec
transport preferred none
transport output lat pad telnet rlogin lapb-ta mop udptn v120 ssh
stopbits 1
line 0/1/0
script dialer lte
no exec
transport preferred none
transport output none
rxspeed 100000000
txspeed 50000000
line 0/1/1
no exec
rxspeed 100000000
txspeed 50000000
line 0/2/0
script dialer lte
modem InOut
no exec
rxspeed 100000000
txspeed 50000000
line vty 0 4
access-class VTY_Control in vrf-also
privilege level 15
transport input telnet ssh
!
scheduler allocate 20000 1000
ntp broadcastdelay 80
ntp update-calendar
ntp server vrf COVA-(Host) 10.193.242.97 prefer

George, I see that you added a reference to the Cellular 0/2/0 interface, (see below) but saw no other reference for  "NAT Outside"? Is no NAT table required?


interface Cellular0/2/0

ip nat outside

Indeed, I forgot to add that...

 

interface Cellular0/2/0

ip nat outside

 

I am really curious to know if that works...

George, Thank You Very Much.  Your configuration seems to have corrected the issue and my Verizon connection is staying up. Thank you also for the explanation as to why it was happening. Now I just need to figure out how to get the Event Manager script to work with the new cards. I'll start a new thread for that.

 

Thank You again......Jeff 

Review Cisco Networking for a $25 gift card