Got it

USG6350 dual HRP IPSec encrypted DSVPN tunnel cannot go UP

Latest reply: Oct 30, 2018 08:02:43 732 1 0 0 0

Issue Description

The customer has 2 hubs (USG6350) running HRP load balanced mode, which  is working well.

He has configured DSVPN (dual HUB) on the USG’s and he has an AR169 acting as a spoke.


Everything works perfectly until he adds IPSec encryption to the tunnels. The customer is using the local IP addresses of G1/0/0 for the Hubs and the Dialer IP interface of the spoke.

1

 2

3

When he adds encryption the AR can only connect to only hub (master), bet he cannot connect to the second hub (slave).

If he reboots the master, the slave becomes the new master and ospf forms fine and the tunnel is encrypted.

If he removes encryption from all tunnels (HUB 1, HUB 2 and SPOKE 1) DSVPN works perfectly, the spoke registers with both hubs in NHRP and OSPF neighbours establish fine, this issue relates to encryption.


Below you can see the topology:


22695592ff7b4ed9a18e9377e453970f

Handling Process

1. We've started to check the configuration on the USG and AR and the customer was using hot-standby with active-standby mode. The IPSec parameters were ok so we requested to collect debugging information for the IPSec.

2. We have checked the debugging  and we saw that when the spoke (AR) send the negotiation packets to standby USG, this device will drop them.

   4


After checking this behavior, we suggested the customer to delete the ipsec configuration of the tunnel interface, and then add the configuration using the keyword “alone” on the USG6300:

ee6fbebc700540f689fa7bb27008fef1

 The keyword “alone” indicates that the tunnel is not backed up.


Solution

In this situation, please delete the IPSec configuration and add it using the keyword “alone”

This article contains more resources

You need to log in to download or view. No account? Register

x

The debugging logs are very useful, it can help us to check the issue easily, but from the log, it means the interface status is not correct, but the solution is to add key word "alone", what is the relationship between, can you describe more detailly
View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.