Dual Hub Single DMVPN Layout using EIGRP

Unanswered Question
Aug 31st, 2007


I try to setup an demo lab for DMVPN, what I use 2*2811, 2*2801 and 1*1841 ISR routers. Two HUB and two Spokes are in my design the fifth router represent the Internet and iterconnect the other four routers. VPNs are working fine between the HUB and spokes, the problem appear when I simulate the primary HUB failure, when recover this node the node doesn1t want to form IPSec session with the others.

If you have any idea please share with me.

bye FCS

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
didyap Thu, 09/06/2007 - 06:53

If you are using RSA-SIG for authentication check if you are able to complete ISAKMP phase 2 and the packets are not getting dropped. The packets may be dropped because of large size of the signatures. If you are using pre shared keys make sure you have configured pre-shared in keyring using VRF PUBLIC using command "Crypto keyring myring VRP PUBLIC" on the Hub devices.


This Discussion