Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Attention: The Community will be in read-only mode on 12/14/2017 from 12:00 am pacific to 11:30 am.

During this time you will only be able to see content. Other interactions such as posting, replying to questions, or marking content as helpful will be disabled for few hours.

We apologize for the inconvenience while we perform important updates to the Community.

New Member

ISM-VPN-39 breaks High Availality GRE IPSec

Hello everyone,

Just wonder if anyone have any experience configuring ism-vpn-39 with gre over ipsec using HSRP virtual IP as the tunnel source and destination endpoints? My configuration is working perfectly fine if I disable ism-vpn-39 with "no crypto slot 0". But as soon as I re-enable this accelerator, all the tunnels drop. I'm using the latest IOS 15.3-2T.

I've also been having headache with this module and older IOS versions, it either crashes the router or strangely breaks the traffic between the router and the installed switch service module (SM-ES3G-24-P) after about 3 hours of operation. The fix was to upgrade to the latest IOS but then it causes the probem above. Thanks for insight.

1 REPLY

ISM-VPN-39 breaks High Availality GRE IPSec

Hi,

There seems to a few bugs that are resolved in the latest 15.3-2T but seem to still have the same symptoms that you are experiencing. Crashing of the module when icmpv6 pings are issued to the router, the ism-vpn not encapsulating esp packets..etc. You may need to open a tac case to validate that this bugs are fixed and are in a verfied or resolved state.

Here is a link to the release notes and there are quite a few bugs related to the ism-vpn module.

http://www.cisco.com/en/US/docs/ios/15_3m_and_t/release/notes/153-2TCAVS.html#wp56114

Tarik Admani
*Please rate helpful posts*

Tarik Admani *Please rate helpful posts*
419
Views
0
Helpful
1
Replies
CreatePlease to create content