![]() *Nov 28 16:19:23.222: NHRP: Send Registration Request via Tunnel1 vrf 0, packet size: 84 *Nov 28 16:19:08.742: NHRP: Send Registration Request via Tunnel1 vrf 0, packet size: 84 *Nov 28 16:19:00.866: NHRP: Send Registration Request via Tunnel1 vrf 0, packet size: 84 ![]() still cant get the eigrp to work, and when i did debug nhrp i get these. To be clear I removed the tunnel protection and now I am runinng DMVPN over internet ( without IPSec ). IPSEC FLOW: permit 47 host BRANCH_IP/ host HEADOFFICE_IPĪnd sometimes the Session status is Down Negotiating IKE SA: local BRANCH_IP/500 remote HEADOFFICE_IP/500 Inactive *Nov 28 15:33:49.002: ISAKMP:(0:89:HW:2):deleting SA reason "Death by retransmission P1" state (I) MM_KEY_EXCH (peer HEADOFFICE_IP) *Nov 28 15:32:58.290: IPSEC(crypto_map_check_encrypt_core): mtree says we have SA but couldn't find current outbound SA. *Nov 28 15:31:58.266: IPSEC(crypto_map_check_encrypt_core): mtree says we have SA but couldn't find current outbound SA. *Nov 28 15:30:58.242: IPSEC(crypto_map_check_encrypt_core): mtree says we have SA but couldn't find current outbound SA. *Nov 28 15:30:00.506: ISAKMP:(0:81:HW:2):deleting SA reason "Death by retransmission P1" state (I) MM_KEY_EXCH (peer HEADOFFICE_IP) *Nov 28 15:30:00.506: ISAKMP:(0:81:HW:2): Phase 1 negotiation failed with DPD active deleting IKE/IPSec SAs *Nov 28 15:29:58.218: IPSEC(crypto_map_check_encrypt_core): mtree says we have SA but couldn't find current outbound SA. ![]() *Nov 28 15:28:58.194: IPSEC(crypto_map_check_encrypt_core): mtree says we have SA but couldn't find current outbound SA. *Nov 28 15:28:58.190: IPSEC(crypto_map_check_encrypt_core): mtree says we have SA but couldn't find current outbound SA. *Nov 28 15:27:58.162: IPSEC(decapsulate): error in decapsulation crypto_ipsec_les_fs *Nov 28 15:27:43.706: map_db_find_best did not find matching map *Nov 28 15:27:43.390: map_db_find_best did not find matching map *Nov 28 15:27:38.230: ISAKMP: Trying to decrement ipsec count below 0 *Nov 28 15:27:37.990: ISAKMP: Trying to decrement ipsec count below 0 *Nov 28 15:27:37.978: ISAKMP:(0:0:N/A:0):Can't decrement IKE Call Admisstion Control stat outgoing_negotiating since it's already 0. I did some debugs and got the following errors on the branch router, the subnet 192.168.10.x is the one I am having problem with Set security-association lifetime seconds 36000 īelow is the revelent configuration of Both offices and they are connected though Point to multipoint linksĬrypto ipsec transform-set MINE esp-3des esp-md5-hmac Then I need to issue "clear crypto isakmp" and "clear crypto session". When I log into my branch router I can see that only 1 tunnel is working, when i do sh crypto sessions, it says NO IKE in status.
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |