Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

dm
New Member

flexvpn (ikev2) , dmvpn (mGRE), tunnel ivrf and fvrf

Hello!

 

I see strange spoke behaviour in case of  the same ivrf and fvrf on spoke interface:

someting like this

interface Tunnel2
 ip vrf forwarding test
 ip address 172.20.1.5 255.255.255.0
 no ip redirects
 ip mtu 1416
 ip nhrp map 172.20.1.1 192.168.42.150
 ip nhrp map multicast 192.168.42.150
 ip nhrp network-id 10
 ip nhrp nhs 172.20.1.1
 ip nhrp registration no-unique
 tunnel source GigabitEthernet1.777
 tunnel mode gre multipoint
 tunnel vrf test
 tunnel protection ipsec profile default

 

in this case I always can ping hub from this interface  , but not always another spoke-
if it starts working it works until some timeout, sometimes it doesn't work from CSR1000v reload.

I always see another spoke in nhrp table, but sometimes there is even no tries to open ikev2 connection, sometimes there is ikev2 , but 0 packets for decription on this spoke side.

Sometimes clear ip nhrp  helps, but not always.

I can't reproduce this, it happens often, but I don't know how to reproduce.

There is no such problem if only fvrf or ivrf is set.

Not sure , but looks like setting different fvrf and ivrf works OK too.

 

Any ideas what is wrong here?

 

Thank you!

 

288
Views
0
Helpful
0
Replies
CreatePlease login to create content