cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1263
Views
0
Helpful
3
Replies

DMVPN tunnels stay up

pspy
Level 1
Level 1

Hello, I need to change the hub's public IP-address. The only way to reach the spokes is through the tunnel.

Action plan was to change the nhrp maps in the spokes first, then at last to change the hubs public IP. This didn't worked, because the tunnels always stay up and keep the "old" IP address.

I added ISKMP keepalives, tunnel nhrp holdtime and tunnel keepalive; but without success.

The only way to get the spokes accepting the new IP-address, is to shut,no shut the tunnel. But this cuts my own branch off.

Question: Does anyone knows a way, that lets DMVPN tunnels realize a connection loss, clear nhrp cache and rebuild a tunnel to a new destination without rebooting spokes?

Thanks and regards Peter

1 Accepted Solution

Accepted Solutions

ggilbert
Cisco Employee
Cisco Employee

Peter,

Thanks for responding and letting me know. I do appreciate it.

Cheers

Gilbert

View solution in original post

3 Replies 3

ggilbert
Cisco Employee
Cisco Employee

Peter,

Would it be possible to create a Second Tunnel interface will all the new information and then change the IP address on the hub.

Now you will have connectivity from your spokes to the hub.

Delete the old tunnel interface.

Will that work?

Hope this helps.

Thanks

Gilbert

Hi Gilbert

thanks a lot for your suggestion.

I tried it, but it didn't work. Creating a second tunnel-ifc was ok, but the IP address must be in another range. Also the original tunnel crashed after applying the crypto rules.

I found some new commands on CCO, which our actual installed IOS doesn't support yet. i.e. "clear ip nhrp" and others.

This morning I performed the migration succesfully! The solution was to install a "out-of-band" backdoor on every spoke. Like an ssh or https access. This way, after changing the nhrp mapping, it was possible to login via ssh, then shut/no shut the tunnel-ifc. This way, the router activated the new mapping and a new tunnel was built to the hubs new IP-address.

Regards Peter

ggilbert
Cisco Employee
Cisco Employee

Peter,

Thanks for responding and letting me know. I do appreciate it.

Cheers

Gilbert

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: