04-24-2012
07:05 AM
- last edited on
02-21-2020
11:52 PM
by
cc_security_adm
Hi All,
Currently working on a DVPN project and having trouble getting things working correctly. have been working primarily from this document: http://www.cisco.com/en/US/tech/tk583/tk372/technologies_white_paper09186a008018983e.shtml
I have 3 seperate sites. HQ, Site1 and Site2. each site is using NAT so it has internet access which is working correctly as far as I can tell. just to get things working, I have created a static route to the other LAN segment over the Tunnel interface.
The problem is that pings from the spoke to the hub router works fine, however the hub cannot ping the spoke.
The "sh dmvpn" command gives the following outputs:
The "sh ip route" command gives the following outputs:
Lastly, here is the full configuration for both devices;
When I ping from Site1 to HQ I can see the encryption counters going up (using sh crypto ipsec sa) whereas if I ping from HQ to Site1, the counters dont go up and neither do the interface counters on Tunnel0 so clearly HQ is not passing any traffic over the tunnel... but I dont know why!
Very new to DMVPN, think i may have taken on a little too much with this project but its too late now.
Any help much appreciated.
Thanks,
apilbeam
04-24-2012 09:49 AM
DMVPN is a multiaccess network. Try removing "
ip route 10.10.10.0 255.255.255.0 Tunnel0" and replace Tunnel0 with the next-hop ip address.
Dan
04-24-2012 04:39 PM
I built a couple of DMVPN networks using the Cisco Configuration Professional tool. It has a nice wizard, was simple and worked on the first try.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide