Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

flexvpn (ikev2) , dmvpn (mGRE), tunnel ivrf and fvrf



I see strange spoke behaviour in case of  the same ivrf and fvrf on spoke interface:

someting like this

interface Tunnel2
 ip vrf forwarding test
 ip address
 no ip redirects
 ip mtu 1416
 ip nhrp map
 ip nhrp map multicast
 ip nhrp network-id 10
 ip nhrp nhs
 ip nhrp registration no-unique
 tunnel source GigabitEthernet1.777
 tunnel mode gre multipoint
 tunnel vrf test
 tunnel protection ipsec profile default


in this case I always can ping hub from this interface  , but not always another spoke-
if it starts working it works until some timeout, sometimes it doesn't work from CSR1000v reload.

I always see another spoke in nhrp table, but sometimes there is even no tries to open ikev2 connection, sometimes there is ikev2 , but 0 packets for decription on this spoke side.

Sometimes clear ip nhrp  helps, but not always.

I can't reproduce this, it happens often, but I don't know how to reproduce.

There is no such problem if only fvrf or ivrf is set.

Not sure , but looks like setting different fvrf and ivrf works OK too.


Any ideas what is wrong here?


Thank you!


CreatePlease login to create content