Cisco WAN :: 2911 - DMVPN Tunnel 0 Up - Line Protocol Down

Jul 8, 2011

We have a 6 spoke DMVPN setup. Five of the six spokes work fine. On the 6th spoke, a 2911, we have created a Tunnel0. Other spokes and the hubs can ping it's ip, but it can't ping itself. When we do a show interface it shows the Tunnel 0 is up, but the protocol is down. What does that mean?

View 4 Replies


ADVERTISEMENT

Cisco :: FastEthernet0/0 Is Up / Line Protocol Is Down

Jan 26, 2013

I was working on a problem the other day and came across something that I had seen before but never given much thought. I had a router with a switch connected to it and the interface was showing as Ethernet0 is up, line protocol is down. The problem in the end turned out to be a cable that had fell out because it was not connected correctly, but I was able to replicate this interface status on a router (FastEthernet0/0 is up, line protocol is down), and NO cable was attached to the interface.I've had a look on the internet but cant seem to find a good answer, so does anybody else know why this status is shown on the router? Remember, NO cable is connected to the interface so it isn't a speed or duplex problem

View 5 Replies View Related

Cisco :: BVI1 / Line Protocol Is Down?

Sep 7, 2009

how to bring this interface back up? It's a 1252 with 80211.n.I started configuring it with CLI and then was using the web interface. I made a change on the web interface and it caused the AP to hang. I rebooted it and can access via Hyperterminal, but I cannot ping the IP address nor bring it up in the web interface any longer.I tried the "No shut" command in the BVI1 interface.

View 4 Replies View Related

Cisco WAN :: 6506 OC3 Troubleshooting Line Up Protocol Down

Jan 21, 2013

I'm replacing a PA-POS-OC3-SM with PA-POS-1OC3 in a flex Wan module (WS-X6582-2PA) in Cisco 6506 using WS-SUP32P-GE PISA.I have a hard time bringing the "protocol up. the status I see is line up and protocol down. Debug shows (attached) no comunication with the edge router but when i put the older PA (PA-POS-OC3-SM ) back evertything works fine and older PA has been running for many years without the issue. I'm replacing older PA is becuase this is going EOL. I had opened a TAC case but the TAC engineer added no value. [code]

View 2 Replies View Related

Cisco VPN :: AES256 / 3 DMVPN Tunnel With Different Encryption To The Same Destination?

Apr 25, 2013

i have a general Question regarding buildings SA´s between two peers.Can I establish more than one SA between two Peers with the same IP Address?Actually I have 3 DMVPN´s running in parallel in different VRF´s using the same SA.They have all the same IPSEC encryption AES256.Now I need to reduce the encryption to 3DES in one of the three DMVPN´s.Is that possible or do I need a differnet IP Address so that the SA Pair is unique?Thats how I stared, with a Phase 2 failure that it is not acceptable.

crypto keyring preshared
  pre-shared-key address x.x.x.x key ....ncvnbxcnbLsaYiKtxc4ex4U99Tn...
  pre-shared-key address x.x.x.x key ....qerqwerJLsaYiKtxc4ex4U99Tn...
  pre-shared-key address 0.0.0.0 0.0.0.0 key ....JLsaYiKtxewrc4ex4U99Tn...

[code]....

View 4 Replies View Related

Cisco VPN :: 1811 / Packet Loss Via DMVPN Tunnel But Not Across WAN

May 12, 2011

Scenario:
 
Central Router (WAN: 1.1.1.1) <--> Internet <--> (WAN: Dynamic IP) Branch RouterTunnel 172.31.254.1/26                                     Tunnel 172.31.254.9/26
 
Central router is a Cisco 1811 running IOS c181x-advipservicesk9-mz.151-4.M.bin.Branch router is a Cisco 1941 running IOS c1900-universalk9-mz.SPA.151-4.M.bin.
 
When I do a Ping test directly from the branch to central router over the Internet I have no packet loss:
 
branch#ping 1.1.1.1 source GigabitEthernet 0/0 repeat 1000Type escape sequence to abort.Sending 1000, 100-byte ICMP Echos to 1.1.1.1, timeout is 2 seconds:Packet sent with a source address of 192.168.0.100!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!(...)!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!Success rate is 100 percent (1000/1000), round-trip min/avg/max = 40/41/60 msbranch#
 
When doing a Ping test over the DMVPN tunnel (which is using the WAN IP as source) I see packetloss.
 
branch#ping 172.31.254.1 source Tunnel 3 repeat 1000Type escape sequence to abort.Sending 1000, 100-byte ICMP Echos to 172.31.254.1, timeout is 2 seconds:Packet sent with a source address of 172.31.254.9!!!!!!!!!!.!!!!!!!!!!.!.!!!!!!.!!!!!..!!!!!!..!!!!!!!!.!!.!!!!!.!!!!!!!!!!!!.!!!!!.!!!.!!!!!!!!!!!..!!!!.!.!.!!!!!.!!!!!!!!!.!..!!!.!.!!!!!.(...)!!!!!!.!!!.!!!!.!!!!.!.!!.!!!!!!!!!!!!!!!.!!.!!!!!!!!!.!!!.!!.!.!!!!!...!!!!!!!!!!..!!!!!!Success rate is 79 percent (795/1000), round-trip min/avg/max = 40/43/568 msbranch#
 
Central:

interface Tunnel0 description Testing (DMVPN) bandwidth 10000 ip address 172.31.254.1 255.255.255.192 no ip redirects ip mtu 1400 ip nhrp authentication testing ip nhrp map multicast dynamic ip nhrp network-id 1 ip nhrp holdtime 600 ip nhrp redirect ip tcp adjust-mss 1360 no ip split-horizon eigrp 1 tunnel source FastEthernet1 tunnel mode gre multipoint tunnel key 100003 tunnel bandwidth transmit 10000 tunnel bandwidth receive 10000 tunnel protection ipsec profile secure_profile shared
 
Branch:
 
interface Tunnel3 description Testing (DMVPN) bandwidth 2000 ip address 172.31.254.9 255.255.255.192 no ip redirects ip mtu 1400 ip nhrp authentication testing ip nhrp map multicast 1.1.1.1 ip nhrp map 172.31.254.1 1.1.1.1 ip nhrp network-id 1 ip nhrp holdtime 300 ip nhrp nhs 172.31.254.1 ip nhrp shortcut ip nhrp redirect ip tcp adjust-mss 1360 no ip split-horizon eigrp 1 delay 1000 tunnel source GigabitEthernet0/0 tunnel mode gre multipoint tunnel key 100003 tunnel bandwidth transmit 2000 tunnel bandwidth receive 2000 tunnel protection ipsec profile secure_profile shared
 
Crypto parameters on both central and branch routers:
 
crypto isakmp policy 1 authentication pre-share
  crypto ipsec transform-set secure_transform-set esp-3des esp-sha-hmac mode transport
  crypto ipsec profile secure_profile set transform-set secure_transform-set
 
I disabled CEF on both the central and branch routers and no success.  The EIGRP neighborship appears to be stable.

View 4 Replies View Related

Cisco WAN :: 2911 Has Unknown Protocol Drops?

Mar 10, 2012

I have issues to connect Cisco 2911 to HP switch. I disable CDP on the LAN port, router at A end is ok, but the unknow protocal drops as same as before at B site. It happend around every 30sec. When I transfer a file from one end to the other end. It always disconnect every 25 second. HP Switch is not configure trunk as it work as a plain network

View 3 Replies View Related

Cisco WAN :: Fast Ethernet Is Up / Line Protocol Down 1841

Aug 2, 2012

I have a cisco 1841 whose LAN interface is showing status as "Fastethernet 0/1 is up , line protocol is down" the duplex and speed settings in the Router are in Auto mode and the Router was working fine till now , when i changed the duplex settings to duplex full , speed 100 the ping replies comes back with 5-6 replies then the link dies again..

View 1 Replies View Related

Cisco WAN :: 3845 Bandwidth Limitation On DMVPN Tunnel Interfaces

Apr 23, 2012

So in our DMVPN network, we have this Cisco 3845 hub router that is connected via a DS3 to the Internet, and our spoke sites usually have a broadband connection that typically have a maximum of 1Mbps upload capacity. We are getting ready to add a few more sites to our network that are connected to the Internet with 10Mbps upload speeds (and 50Mbps download). Spoke site routers are usually 800 series ISRs. We have seen spikes of 8-10Mbps on the hub router so far. So the question is that a site with 10Mbps upload speed transmit to the full capacity over a DMVPN tunnel or is it limited by other factors? What are those factors?

View 4 Replies View Related

Cisco VPN :: 886 DMVPN Tunnel Sourced Via Loop Back Error

Nov 22, 2012

I am having a hard time trying to configure DMVPN with the tunnel being sourced via a loopback interface. All routers are Cisco 886 routers which don't have L3 ports.That is why I used SVI interfaces, and have configured the L2 ports (Fa0, Fa1, etc.) with the command switchport access vlan.The problem is that I am receiving Invalid SPI error's only on the Hub router and I have no clue what could be the problem, because they use exactly the same parameters for IPsec. [code]

View 1 Replies View Related

Cisco WAN :: Network Slow Down With DmVPN Tunnel On 2811 Router?

May 15, 2013

We are facing network heavy and slow performance at one of our remote site, we are using Cisco2800 series router with same IOS on either of the sites.Our WAN network is running on BGP with EIGRP configured and tunnels were configured on either of the sites. As part of the testing I have removed the tunnel to see the performance was ok from Head office to remote branch and the WAN network is getting heavy and slow down when we put the tunnel back in hub and spoke.
 
quick info
 
Cisco 2800 Series router
 IOS: (C2800NM-ADVIPSERVICESK9-M), Version 12.4(15)T1, RELEASE SOFTWARE

View 1 Replies View Related

Cisco WAN :: 1841 - Duplicate Multicast Packets With DMVPN Tunnel

Mar 21, 2013

I have a setup where a spoke (cisco 1841) is sending a multicast feed to a hub (cisco 2951) via a DMVPN tunnel on the Internet. The feed arrives on interface fa0/0 of the cisco 1841 and is forwarded to the tunnel interface.  It is about 160,000 kbit/s and 18 pps. This always looks the same:
 
cisco2951-1-hub#sh run int tu10
!
interface Tunnel10
description DMVPN TUNNEL

[Code]...

View 5 Replies View Related

Cisco Switching / Routing :: 3550 - Line Protocol Flapping

Aug 27, 2012

I work for a Wireless ISP and the device impacted is the back haul radio into the site. I have swapped from a 2950T to a 3550. Replaced the radio, PoE, patch lead. We have re ran the cable up the tower using shielded outdoor cable with a drain wire which has been earthed to an earthing block in the cabinet. We have other devices on the tower not experiencing the issue. We suspect cable interference however am now at a loss to diagnose further.

[Code]....

View 3 Replies View Related

Cisco WAN :: 7609S - Configure Per-tunnel QoS With DMVPN For MPLS Connected Sites?

May 3, 2013

One of the customers has deployed Cisco 7609S in their infrastructure for Branch/RO connectivity. When we tried to configure per-tunnel QoS with DMVPN for MPLS connected sites, we came to know that Cat 6500 and Cisco 7600 series routers don't support this feature.
 
Now, we are looking for suitable replacement of Cisco 7609S. I found a document for configuring above feature on Cisco ASR 1000 series routers, but it has many restrictions always.
 
We are now looking for
 
(a) suitable platform in the league of Cisco 7609S which support above feature.

(b) suitable technology replacement of DMVPN with minimum restrictions.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: 4500 / Interface Is Up / Line Protocol Is Down (not Connect) / Dot1x?

Aug 11, 2011

I configured dot1x on my swicth 4500 series, Here is the interface configration:

interface FastEthernet3/2
description Test dot1x
switchport mode access
load-interval 30
authentication event fail action authorize vlan 800
authentication host-mode multi-host
authentication port-control auto

[code]....
 
When I remove the port-control configuration on the interface, the status change to UP/UP.

View 1 Replies View Related

Cisco WAN :: Serial Up Line Protocol Down On 1900 Router With Single T1 Connection

Jul 11, 2012

Have been battling a router connection to new ATT t1 connection.  Router was configured and sent from sister company to this new location.  We have had ATT tech test circuit and it tests good, had cat5 cable tested from ATT to router, it tests good.    I continue to get serial up/ line protocol down status though and cant communicate to it from wan. 

View 4 Replies View Related

Cisco Switching/Routing :: Unknown Protocol Drops On WAN Interface - 2911

Feb 15, 2012

I have been having following situation on my WAN facing interface on Cisco2911 where the same number of broadcast, multicast and unknown protocol drops is happening. Not sure but some applications are struggling to run over on the WAN.
 
[code]....

View 4 Replies View Related

Cisco :: 2911 Connecting To A Leased Line?

Aug 3, 2012

I have a cisco 2911 set up at one of my sites and it is configured with sub-interfaces as this provides a default gateway to each of the offices.I have just had a 100mb leased line put in and i have a couple of questions regarding the config.let me start by telling you how it is set up .I have 3 HP Procurve switches connected together then that connects to the Cisco and the Cisco connects to a Zywall

HP Switches > Cisco 2911 > Zywall > Internet

We are wanting to remove the Zywall and connect the Cisco to the Leased line box

HP Switches > Cisco 2911 > Leased Line > Internet

The config of the cisco is

G0/0 - is up but no cable connected as this holds the sub-interfaces
G0/1 - Connects the Zywall - 192.168.1.1 (this has firewall rules to forward traffic through)
G0/2 - Leased Line

The way i have configured the sub interfaces is with its own DHCP pool and default router, some of the offices have there own ADSL router and hold there own Internet connection and the default gateway for that is 192.168.xxx.253 and the offices that use the Cisco use default gateway of 192.168.xxx.254

Now my question is how would I move everyone onto the Leased line and get rid of the Zywall ? Would it be as simple as giving the leased line an address and put in a static route to forward all traffic through that connection ? Or am i missing a trick or 2.

View 2 Replies View Related

Cisco VPN :: 1841 IPsec Tunnel Protocol Down After A Minute?

Apr 23, 2013

I have a strange issue where im able to get an ipsec tunnel from tha cisco 1841 to a linksys/cisco RV016 for about a minute and ping/encrypt packets across the lin for about a minute before it goes down. I tried various configuration and it all results in the tunnel coming up for a minute then going down. I'm not sure if im hitting a bug and on which decide of if im doing something wrong. 
 
RV016 firmware 2.0.18
cisco 1841: C1841-ADVENTERPRISEK9-M), Version 12.4(24)T
 
my config
 
no crypto isakmp default policy
!
crypto isakmp policy 1
encr 3des
hash md5
authentication pre-share
group 2

[code]....

View 3 Replies View Related

Cisco Infrastructure :: 2911 TS Causing A-sync Line Lock Out

Oct 31, 2011

I have a brand new 2911-TS running 2900-universalk9-mz.SPA.151-4.M1.  I have connected the async lines to several devices including ASA5510's, 7206V XR and 6506es.  I'm experiencing issues where I go to connect to the console port of one of my devices and my access is denied as if the port was already in a session.  I clear the line and try again, same response.  If I swap that line with a known functioning line I see lines and lines of output as if the device I was trying to connect to was constantly sending data to the console port.  I've not had this problem on any of my older Cisco terminal servers.  I opened a TAC case and they had me RMA the HWIC module.  I cannot find any information about setting some sort of buffer limit or session timeout.  I feel this is a configuration, or mis-configuration issue. 

View 8 Replies View Related

Cisco WAN :: 2911 - Test Load On Line / Big Datagram Size?

Jan 12, 2012

Network 
 
                        2 Bundled T1(3Mbps)
2911---------------------------------------------------------2911
 
 
I am pinging across the Wan to test the circuit and it is pinging fine with the default extended ping 5 repeat count and 100 Datagram size. I was told that I need to up the repeat count to 1000 and the datagram size to 17999 to test the line. Also when performing this test Txload is 255/255.Is this really needed to test the load on the line, that big of a datagram size?

View 5 Replies View Related

Cisco WAN :: 2911 - Need PVDM When Use HWIC-2CE1T1-PRI For Leased Line

Oct 11, 2012

We plan migrate an old existing WAN architecture based on legacy data serial links. These links will be consolidated on a E1 channalized card.
 
My question :
 
Is the HWIC-2CE1T1-PRI need a PDVM DSP ressources on router  to oparate for data leased lines or no?
 
The VWIC3-1MFT-T1/E1 will be used for the backup dial in ISDN connexions? this type of cards a PVDM DSP ressources for data connexions or no?
 
ISR router are 2911.

View 5 Replies View Related

Cisco Routers :: RV082 V3 Load Balancing (Protocol Binding) With IPsec Tunnel?

Mar 14, 2013

We have tried a variety of options in an attempt to use Load Balancing (Protocol Binding) with an RV082 that has a site to site IPsec tunnel with another RV082. Both are v3.
 
Here is the issue. We have dual ISPs, one has great bandwidth, but we incur overages. The other has mediocre bandwidth, but has unlimited usage.
 
GROUP1 - We want most PCs to use the "unlimited" ISP for general surfing, email, etc. (Bound all ports for range of internal IPs to ANY dest to WAN1)
 
GROUP2 - We want to use the "faster" ISP for our VPN tunnel (mostly RDP and SIP traffic). (Bound all ports for range of internal IPs to ANY dest to WAN2)
 
So far everything works. The router will route traffic appropriately and GROUP 1 uses WAN1 and GROUP 2 uses WAN2.
 
Unfortunately, sometimes GROUP1 users need access to resources over the VPN (WAN2).
 
There is something not right with the routing. For example GROUP1 can ping and receive responses from devices on the other side of the tunnel, but GROUP1 can't access intranet sites on the other side of the tunnel. They also can't RDP to PCs on the other side of the tunnel.
 
Why does the router correctly route ICMP, but not RDP?
 
We've tried adding additional protocol binding rules for specific ports(80, 3389, etc) and ip ranges (both local and remote) to see if we could force GROUP1 traffic destined via VPN through WAN2, but it doesn't work.
 
Shouldn't VPN tunnels created and configured in the RVs not adhere to protocol binding? It just seems logical to me, but maybe I am missing something.

View 7 Replies View Related

Cisco Switching/Routing :: 2911 - Capture User Who Execute Telnet / Show Line In Log?

Jan 21, 2013

We are running in our DC one of the  CISCO 2911 terminal server which is connected with HP ARC sight logger.
 
it is possible to capture user who execute ‘Telnet” or “show line” in the log, I mean all the command entries by user.
 
How to enable any config on 2911.

View 11 Replies View Related

Cisco VPN :: Zfw VPN Tunnel 2911

Mar 2, 2012

Recently i attempted to build a LAN 2 LAN VPN tunnel from an Asa to a 2911 running zone based firewall.  This was a standard IPSec psk tunnel nothing fancy.  I got the tunnel to establish but i could only get traffic to encap on the Asa side and decap on the 2911 side.  I couldn't get return traffic.I followed this doc here for classic IPSec in the last example. URL

And I am sure the Asa is right I built a ton of those but I am new to zfw.  I did not see anything about a NAT exempt rule.  But since everything uses real IPs instead of NAT I wasnt sure and I could not find any info.  Do I need to do NAT exempt?  If so do you use a route map on the end of you NAT overload config line like in the past?

Also I have a zone-pair to "self" and I was not sure if I needed anything there to be able to ping the inside interface of the 2911 when the tunnel is up from the remote end.

View 7 Replies View Related

Cisco :: GRE Tunnel Has To Be Reset After WAN Line Bounce C2900

Jun 2, 2013

We are facing a strange issue with GRE tunnel. We are using this tunnel from a branch office to Hub office. All other tunnels terminated on Hub router are working fine. Issue with this tunnel is that whenever WAN connection goes down Line protocol on tunnel interface some times comes up and sometimes not (therefore we have to reset the tunnel interface and it comes up). IOS used on this router : c2900-universalk9-mz.SPA.152-1.T2

View 5 Replies View Related

Cisco WAN :: 2911 Router VPN Tunnel And Default Routing?

Feb 16, 2012

I have a Cisco 2911 that I am configuring for a remote site.  I have configured a IPSec Tunnel from our main site ( ASA 5510 ).  The Tunnel is up and I can connect from the main site LAN to the address of the 2911 through the IPSec Tunnel.  The 2911 is equipped with a 16port switch service module.  The switch is configured with an address and I can open a telnet session to the switch.  From that session, I am able to reach hosts on the LAN across the IPSec tunnel.  However, when I open a telnet session to the 2911 router, I cannot reach hosts on the main site LAN from that address.  When I do, the traffic is sent outside of the tunnel instead of inside it.  It works from the service module as traffic between the interfaces have the ACL for insteresting traffic applied, but traffic generated from the address of the 2911 router does not seem to get picked up by the ACL on the IPSec tunnel and it is getting the default route applied and going directly to the outside interface instead of to the tunnel. how to make this work?

View 3 Replies View Related

Cisco VPN :: 2911 - Unable To Access LAN Using Client Tunnel To Router

Sep 4, 2011

I recently purchased a Cisco 2911 to replace my Cisco 1711 router. I copied the  configuration from the Cisco 1711 router to the Cisco 2911 router.  Everything seemed to work correctly except when I VPN tunnel into the Cisco 2911  router using Cisco's VPN client version 5.0. I can ping the router LAN interface from my PC that is VPNed into the  router but I can no longer ping or access the devices on the LAN side of the  router as I did on the Cisco 1711 router. I don’t see errors in the log or hits  blocking anything in the acls. It’s using the same configuration that I had on  the Cisco 1711 router, and this did work on the Cisco 1711. The Cisco 2911  router is running IOS Software, C2900 Software (C2900-UNIVERSALK9-M), Version  15.0(1)M1, RELEASE SOFTWARE (fc1).
 
Here is the VPN clinet portion of the configuration: The LAN is addressed as 192.168.0.0/24. The router LAN interface is 192.168.0.1, which I can ping and access. I can't ping or access anything on the LAN (192.168.0.0/24) beside the router.
 
aaa authentication login vpnclientauth local
aaa authorization network vpngroupauth local
!
crypto isakmp client configuration group remote-clients
key 6 xxxx
pool clients
[Code]....

View 11 Replies View Related

Cisco :: Line Usage In Case Of Show Line On 2500 Series?

Oct 10, 2012

Cisco 2500 series access servers show line usage with the "show line" command:

View 2 Replies View Related

Difference Between Leased Line And DSL Line

Mar 27, 2012

The reason is i want to know the difference between the leased line and the DSL line. The whole thing behind the confusion is, We plan to have a high speed internet connection in our office. We will don't have a branch office or some thing like that. I preffered to have high speed internet in our office. I found in some website that Lease line will have high speed connectivity(Upto 10Gbps). Can i use the lease line or DSL is enough for our office. Our office contains of 82 user who will use internet.

View 2 Replies View Related

Cisco WAN :: 2911/K9 And 2911-Sec/K9 - BOM For Upgrade?

Dec 25, 2011

I am having one router CISCO2911/K9 (Cisco 2911 w/3 GE,4 EHWIC,2 DSP,1 SM,256MB CF,512MB DRAM,IPB). But now my management asking me to upgrade this router as CISCO2911-SEC/K9.
 
What will be the BOM for this up gradation.

View 2 Replies View Related

Cisco WAN :: 861 Router And DMVPN

Nov 24, 2011

There use to be Cisco 851 routers, but lately these routers are replaced with Cisco 861-K9 routers, and these 861 routers doesn't support DMVPN, instead 851 use to be.

Is there any license file we can upload in 861 router for DMVPN capability, if yes may i know the SKU # for that. We have some customers having 6-7 locations and they are planning to have 2 more locations, we implement already DMVPN in there network, if we go with the 87X or 88X router there price is almost double the price of 861.

View 1 Replies View Related

Cisco :: 1941 / IP SLA In Combination With DMVPN?

Sep 5, 2012

I have a problem with my routers (cisco 1941)I'm running a DMVPN network (Hub and spoke)All the hubs are connected to the 2 hubs. With 4 tunnels. (each hub has 2 interfaces to the spokes. the spokes only have one interface to the hubs, so I splitted them and so I now have 4 dmvpn tunnels). one of the interfaces on a hub malfuntioned and because of that the customers had problems with logging in and sending packets. I made this kind of structure because of when one of the tunnels failed the spoke could use the 3 others... BUT, what happened here was that the spoke still tried to use all 4 of the tunnels and because of that I had 25% package loss!So this didn't work. Now I read about IP SLA, but I was wondering of this could work? (I cannot test it on spare routers, and I don't want to implement it and risking a total network failure...) and how to configure it. Should I make 4 different sla processes which I should all 4 track? And when I make the ip routes, how should I make or configure it so that 1 of the tunnels/interfaces fails that the spoke would addapt the routes?

View 1 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved