Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

QOS Problem on DMVPN

Dears

 

I want your help in figuring out the problem in configuration, as I am trying to deploy qos on DMVPN

# Ent  Peer NBMA Addr Peer Tunnel Add State  UpDn Tm Attrb    Target Network
----- --------------- --------------- ----- -------- ----- -----------------
    1     172.23.1.5     172.23.11.5    UP 00:16:57    D     172.23.11.5/32
NHRP group: spoke_group1
 Output QoS service-policy applied: none

 

 

AUBEgypt-RHT-R this router is hub

shooting club is spoke

 

 

 

 

but i can't see the result as expected :

AUBEgypt-RHT-R#show dmvpn detail
Legend: Attrb --> S - Static, D - Dynamic, I - Incomplete
        N - NATed, L - Local, X - No Socket
        # Ent --> Number of NHRP entries with same NBMA peer
        NHS Status: E --> Expecting Replies, R --> Responding
        UpDn Time --> Up or Down Time for a Tunnel
==========================================================================

Interface Tunnel172 is up/up, Addr. is 172.23.11.1, VRF ""
   Tunnel Src./Dest. addr: 172.23.1.1/MGRE, Tunnel VRF ""
   Protocol/Transport: "multi-GRE/IP", Protect "IPSEC_PROFILE"
   Interface State Control: Disabled
Type:Hub, Total NBMA Peers (v4/v6): 1

# Ent  Peer NBMA Addr Peer Tunnel Add State  UpDn Tm Attrb    Target Network
----- --------------- --------------- ----- -------- ----- -----------------
    1     172.23.1.5     172.23.11.5    UP 00:16:57    D     172.23.11.5/32
NHRP group: spoke_group1
 Output QoS service-policy applied: none

 

Crypto Session Details:
--------------------------------------------------------------------------------

Interface: Tunnel172
Session: [0x689D0324]
  IKE SA: local 172.23.1.1/500 remote 172.23.1.5/500 Active
          Capabilities:D connid:1004 lifetime:23:44:18
  Crypto Session Status: UP-ACTIVE
  fvrf: (none), Phase1_id: 172.23.1.5
  IPSEC FLOW: permit 47 host 172.23.1.1 host 172.23.1.5
        Active SAs: 4, origin: crypto map
        Inbound:  #pkts dec'ed 127 drop 0 life (KB/Sec) 4514806/113
        Outbound: #pkts enc'ed 127 drop 0 life (KB/Sec) 4514807/113
   Outbound SPI : 0xA67C0EBD, transform : esp-aes esp-sha-hmac
    Socket State: Open

Pending DMVPN Sessions:

 

 

 

AUBEgypt-RHT-R#show ip nhrp
172.23.11.5/32 via 172.23.11.5
   Tunnel172 created 00:17:17, expire 01:42:42
   Type: dynamic, Flags: unique registered
   NBMA address: 172.23.1.5
   Group: spoke_group1

 

 

 

 

Shooting-Club#show dmvpn detail
Legend: Attrb --> S - Static, D - Dynamic, I - Incomplete
        N - NATed, L - Local, X - No Socket
        # Ent --> Number of NHRP entries with same NBMA peer
        NHS Status: E --> Expecting Replies, R --> Responding
        UpDn Time --> Up or Down Time for a Tunnel
==========================================================================

Interface Tunnel1 is up/up, Addr. is 172.23.11.5, VRF ""
   Tunnel Src./Dest. addr: 172.23.1.5/MGRE, Tunnel VRF ""
   Protocol/Transport: "multi-GRE/IP", Protect "IPSEC_PROFILE"
   Interface State Control: Disabled

IPv4 NHS: 172.23.11.1 RE
Type:Spoke, Total NBMA Peers (v4/v6): 1

# Ent  Peer NBMA Addr Peer Tunnel Add State  UpDn Tm Attrb    Target Network
----- --------------- --------------- ----- -------- ----- -----------------
    1     172.23.1.1     172.23.11.1    UP 00:17:48    S     172.23.11.1/32


Interface Tunnel2 is up/up, Addr. is 172.23.22.5, VRF ""
   Tunnel Src./Dest. addr: 172.23.2.5/MGRE, Tunnel VRF ""
   Protocol/Transport: "multi-GRE/IP", Protect "IPSEC_PROFILE"
   Interface State Control: Disabled

IPv4 NHS: 172.23.22.1 RE
Type:Spoke, Total NBMA Peers (v4/v6): 1

# Ent  Peer NBMA Addr Peer Tunnel Add State  UpDn Tm Attrb    Target Network
----- --------------- --------------- ----- -------- ----- -----------------
    1     172.23.2.1     172.23.22.1    UP 00:17:48    S     172.23.22.1/32

 

Crypto Session Details:
--------------------------------------------------------------------------------

Interface: Tunnel1
Session: [0x669AD6D4]
  IKE SA: local 172.23.1.5/500 remote 172.23.1.1/500 Active
          Capabilities:(none) connid:1007 lifetime:23:43:28
  Crypto Session Status: UP-ACTIVE
  fvrf: (none), Phase1_id: 172.23.1.1
  IPSEC FLOW: permit 47 host 172.23.1.5 host 172.23.1.1
        Active SAs: 2, origin: crypto map
        Inbound:  #pkts dec'ed 134 drop 0 life (KB/Sec) 4437700/52
        Outbound: #pkts enc'ed 133 drop 1 life (KB/Sec) 4437700/52
   Outbound SPI : 0x90A47368, transform : esp-aes esp-sha-hmac
    Socket State: Open

Interface: Tunnel2
Session: [0x669AD5E4]
  IKE SA: local 172.23.2.5/500 remote 172.23.2.1/500 Active
          Capabilities:(none) connid:1008 lifetime:23:43:29
  Crypto Session Status: UP-ACTIVE
  fvrf: (none), Phase1_id: 172.23.2.1
  IPSEC FLOW: permit 47 host 172.23.2.5 host 172.23.2.1
        Active SAs: 2, origin: crypto map
        Inbound:  #pkts dec'ed 133 drop 0 life (KB/Sec) 4409710/55
        Outbound: #pkts enc'ed 133 drop 1 life (KB/Sec) 4409710/55
   Outbound SPI : 0xEEC2E783, transform : esp-aes esp-sha-hmac

 

 

 

36
Views
0
Helpful
0
Replies
CreatePlease to create content