Naufal,
I have found that there a few necessary commands with DMVPN and everything
else is fluff. So you need to get down to make sure the following things
are correct.
Hub,
ip address
ip mtu <You need to subtract enough for the GRE header 24 bytes, if IPsec
transport mode subtract 20 bytes and tunnel mode subtract another 20 bytes.
Also if you use tunnel key then subtract another 4 bytes. This is why you
will typically see 1400 in examples but it really is 1456 if you use IPSec
transport mode and no tunnel-key.>
ip nhrp network-id x
ip nhrp map multicast dynamic
tunnel source <tunnel-source>
tunnel mode gre multipoint
Spoke
ip address
ip mtu <see above notes>
ip nhrp network-id x
ip nhrp map <hub-ip> <hub-nbma>
ip nhrp map multicast <hub-nbma>
ip nhrp nhs <hub-ip>
tunnel source <tunnel-source>
And Last Either
tunnel destination <hub-nbma-ip> (This is DMVPN Phase I)
Or
tunnel mode gre multipoint (This would be for Phase II or III)
If you can verify that the configuration above between the hub and spokes is
correct then most likely it will work. If you can learn those things then
you have now mastered DMVPN
Regards,
Tyson Scott - CCIE #13513 R&S, Security, and SP
Technical Instructor - IPexpert, Inc.
Mailto: <mailto:tscott_at_ipexpert.com> tscott_at_ipexpert.com
Telephone: +1.810.326.1444, ext. 208
Live Assistance, Please visit: <http://www.ipexpert.com/chat>
www.ipexpert.com/chat
eFax: +1.810.454.0130
From: Naufal Jamal [mailto:naufalccie_at_yahoo.in]
Sent: Tuesday, January 26, 2010 12:43 PM
To: Tyson Scott
Subject: RE: DMVPN eigrp flap issue...
HATS OFF TO YOU TYSON!!!!!!!!!
IT WORKED..... would like to know why this missing command caused neighbor
flap...
--- On Tue, 26/1/10, Tyson Scott <tscott_at_ipexpert.com> wrote:
From: Tyson Scott <tscott_at_ipexpert.com>
Subject: RE: DMVPN eigrp flap issue...
To: "'Naufal Jamal'" <naufalccie_at_yahoo.in>, "'Olaniyi Sonubi'"
<sonubi02_at_gmail..com>
Cc: ccielab_at_groupstudy.com
Date: Tuesday, 26 January, 2010, 5:10 PM
Naufel,
You need to add a network-id
On both the hub and spoke.
ip nhrp network-id 1
Regards,
Tyson Scott - CCIE #13513 R&S, Security, and SP
Technical Instructor - IPexpert, Inc.
Mailto: tscott_at_ipexpert.com
Telephone: +1.810.326.1444, ext. 208
Live Assistance, Please visit: www.ipexpert.com/chat
eFax: +1.810.454..0130
-----Original Message-----
From: nobody_at_groupstudy.com [mailto:nobody_at_groupstudy.com] On Behalf Of
Naufal Jamal
Sent: Tuesday, January 26, 2010 11:19 AM
To: Olaniyi Sonubi
Cc: ccielab_at_groupstudy.com
Subject: Re: DMVPN eigrp flap issue...
I am not getting any output for sh ip nhrp detail on both hub and spoke...to
me the config that i sent you for the tunnels seems O.K on both sides..could
this be a bug with GNS3??
--- On Tue, 26/1/10, Olaniyi Sonubi <sonubi02_at_gmail.com> wrote:
From: Olaniyi Sonubi <sonubi02_at_gmail.com>
Subject: Re: DMVPN eigrp flap issue...
To: "Naufal Jamal" <naufalccie_at_yahoo.in>
Cc: "AndreDufour" <Andre.Dufour_at_paetec.com>, ccielab_at_groupstudy.com
Date: Tuesday, 26 January, 2010, 4:14 PM
Kindly check the nhrp mapping for both hub and spoke. Also check the
physical
reliability of the underlying link and be sure it is ok.
Regards,
'Niyi
On Tue, Jan 26, 2010 at 4:48 PM, Naufal Jamal <naufalccie_at_yahoo.in> wrote:
The sequence number is not increasing and the spokes are not showing any
neighbors... getting more curious to know what could have went missing..I am
imitating a customer network which looks like the same...
--- On Tue, 26/1/10, Dufour, Andre <Andre.Dufour_at_PAETEC.com> wrote:
From: Dufour, Andre <Andre.Dufour_at_PAETEC.com>
Subject: RE: DMVPN eigrp flap issue...
To: "Olaniyi Sonubi" <sonubi02_at_gmail.com>, "Naufal Jamal"
<naufalccie_at_yahoo..in>
Cc: "ccielab_at_groupstudy.com" <ccielab_at_groupstudy.com>
Date: Tuesday, 26 January, 2010, 2:52 PM
Do you have static routes for the interfaces of your eigrp neighbors? If
not,
throw them in to avoid recursion issues. Unlike p2p GRE, multipoint GRE
recursion issues are not so easily seen.
Andre
-----Original Message-----
From: nobody_at_groupstudy.com [mailto:nobody_at_groupstudy.com] On Behalf Of
Olaniyi Sonubi
Sent: Tuesday, January 26, 2010 9:48 AM
To: Naufal Jamal
Cc: ccielab_at_groupstudy.com
Subject: Re: DMVPN eigrp flap issue...
Naufal,
Did the seq number increased? If not then no reliable packets have been
received from the neighbours. Do a show ip eigrp neighbour at the spoke's
side
to see if there is neighbour relationship.
Regards,
'Niyi
On Tue, Jan 26, 2010 at 3:08 PM, Naufal Jamal <naufalccie_at_yahoo.in> wrote:
> I gave bandwidth 128000 on the tunnel at hub and cleared eigrp neigh
> but Q count still 1
>
> --- On *Tue, 26/1/10, Olaniyi Sonubi <sonubi02_at_gmail.com>* wrote:
>
>
> From: Olaniyi Sonubi <sonubi02_at_gmail.com>
>
> Subject: Re: DMVPN eigrp flap issue...
> To: "Naufal Jamal" <naufalccie_at_yahoo.in>
> Cc: "Farrukh Haroon" <farrukhharoon_at_gmail.com>, ccielab_at_groupstudy.com
> Date: Tuesday, 26 January, 2010, 1:52 PM
>
>
> Naufal,
>
> Put a bandwidth statement on the tunnel at the hub.
>
> HTH.
>
> 'Niyi CCIE#23833
>
> On Tue, Jan 26, 2010 at 2:24 PM, Naufal Jamal
> <naufalccie@yahoo.in<http://mc/compose?to=naufalccie@yahoo.in>
> > wrote:
>
>> Hi ,
>>
>> I am reaching the destination thru eigrp...
>>
>> I am using eigrp on FR network to exchange the routing info between
>> the spokes.i removed eigrp from the FR and getting the following. I
>> wish to keep eigrp as the protocol for both dmvpn and FR cos I have
>> seen it working on a customer network...
>>
>> HUB(config-router)#do sh ip eigrp ne
>> IP-EIGRP neighbors for process 10
>> H Address Interface Hold Uptime SRTT RTO Q
>> Seq
>> Typ
>> e
>> (sec) (ms) Cnt
>> Num
>> 1 10..0.0.2 Tu0 11 00:00:59 1 5000 1
0
>> 0 10.0.0.3 Tu0 13 00:01:11 1 5000 1
0
>>
>>
>> retry limit exceeded message coming up...
>>
>>
>> --- On Tue, 26/1/10, Farrukh Haroon
>> <farrukhharoon@gmail.com<http://mc/compose?to=farrukhharoon@gmail.com
>> >>
>> wrote:
>>
>> From: Farrukh Haroon
>> <farrukhharoon@gmail.com<http://mc/compose?to=farrukhharoon@gmail.com
>> >
>> >
>> Subject: Re: DMVPN eigrp flap issue...
>> To: "Naufal Jamal"
>> <naufalccie@yahoo.in<http://mc/compose?to=naufalccie@yahoo.in>
>> >
>> Cc: ccielab_at_groupstudy.com
>> <http://mc/compose?to=ccielab@groupstudy.com>
>> Date: Tuesday, 26 January, 2010, 12:17 PM
>>
>> How are you reaching the tunnel destination? Through EIGRP, another
>> IGP or static routes?
>>
>> Regards
>>
>> Farrukh
>>
>> On Tue, Jan 26, 2010 at 3:06 PM, Naufal Jamal
>> <naufalccie@yahoo.in<http://mc/compose?to=naufalccie@yahoo.in>>
>> wrote:
>>
>> Hey Experts,
>>
>>
>> I need some valuable help from you on the scenario below:
>>
>>
>> 1) I am working out dmvpn PHASE 1 on gns3.with 1 HUB and 2 spokes..
>>
>>
>> 2)I have advertised 1.1.1.0 and 10.0.0.0 networks in eigrp
>>
>> I have given "eigrp stub connected" on both the spokes.
>>
>> MY eigrp neigh looks like this:
>>
>>
>> HUB#sh ip eigrp ne
>>
>> IP-EIGRP neighbors for process 10
>>
>> H Address Interface Hold Uptime SRTT RTO Q
>> Seq
>>
>> Typ
>>
>> e
>>
>> (sec) (ms) Cnt
>> Num
>>
>> 3 10.0.0.2 Tu0 13 00:00:06 1 4500 1
0
>>
>> 2 10.0.0.3 Tu0 11 00:00:12 1 5000 1
0
>>
>> 1 1.1.1.3 Se0/0..1 151 00:12:27 1 5000 0
>> 14
>>
>> 0 1.1.1.2 Se0/0.1 142 00:12:51 372 2232 0
>> 13
>>
>>
>> 2)FR works fine but my neighborships flap like anything..
>>
>>
>> PLS LET ME KNOW IF YOU WANT ANY DEBUG OUTPUTS ON THIS SCENARIO....
>>
>>
>> HUB#sh run int s0/0.1
>>
>> Building configuration...
>>
>>
>> Current configuration : 188 bytes
>>
>> !
>>
>> interface Serial0/0.1 multipoint
>>
>> ip address 1.1.1.1 255.255.255.0
>>
>> no ip split-horizon eigrp 10
>>
>> frame-relay map ip 1.1.1.2 101 broadcast
>>
>> frame-relay map ip 1.1.1.3 301 broadcast
>>
>> end
>>
>>
>> interface Tunnel0
>>
>> ip address 10.0.0.1 255.255.255.0
>>
>> no ip redirects
>>
>> ip nhrp authentication cisco
>>
>> ip nhrp map multicast dynamic
>>
>> no ip split-horizon eigrp 10
>>
>> tunnel source Serial0/0.1
>>
>> tunnel mode gre multipoint
>>
>> tunnel key 123
>>
>> end
>>
>> ------
>>
>> SPOKE 1
>>
>>
>> interface Tunnel0
>>
>> ip address 10.0.0.3 255.255.255.0
>>
>> no ip redirects
>>
>> ip nhrp authentication cisco
>>
>> ip nhrp map multicast 1.1.1.1
>>
>> ip nhrp map 10.0.0.1 1.1.1.1
>>
>> ip nhrp nhs 10.0.0.1
>>
>> tunnel source Serial0/0
>>
>> tunnel destination 1.1.1.1
>>
>> tunnel key 123
>>
>> end
>>
>>
>> SPOKE1(config)#do sh run int s0/0
>>
>> Building configuration...
>>
>>
>> Current configuration : 224 bytes
>>
>> !
>>
>> interface Serial0/0
>>
>> ip address 1.1.1.3 255.255.255.0
>>
>> encapsulation frame-relay
>>
>> serial restart_delay 0
>>
>> frame-relay map ip 1.1.1.1 401 broadcast
>>
>> frame-relay map ip 1.1.1.2 401 broadcast
>>
>> no frame-relay inverse-arp
>>
>> end
>>
>>
>> SPOKE1(config)#
>>
>> ------
>>
>>
>> SPOKE2
>>
>>
>> interface Tunnel0
>>
>> ip address 10.0.0.2 255.255.255.0
>>
>> no ip redirects
>>
>> ip nhrp authentication cisco
>>
>> ip nhrp map multicast 1.1.1.1
>>
>> ip nhrp map 10..0.0.1 1.1.1.1
>>
>> ip nhrp nhs 10.0.0.1
>>
>> tunnel source Serial0/0
>>
>> tunnel destination 1.1.1.1
>>
>> tunnel key 123
>>
>> end
>>
>>
>> SPOKE2(config)#do sh run int s0/0
>>
>> Building configuration...
>>
>>
>> Current configuration : 224 bytes
>>
>> !
>>
>> interface Serial0/0
>>
>> ip address 1.1.1.2 255.255.255.0
>>
>> encapsulation frame-relay
>>
>> serial restart_delay 0
>>
>> frame-relay map ip 1.1.1..1 201 broadcast
>>
>> frame-relay map ip 1..1.1.3 201 broadcast
>>
>> no frame-relay inverse-arp
>>
>> end
>>
>>
>>
>>
>>
>> The INTERNET now has a personality. YOURS! See your Yahoo! Homepage.
>>
>>
>>
>>
>> Blogs and organic groups at http://www.ccie.net
>>
>>
>> _____________________________________________________________________
>> __
>>
>> Subscription information may be found at:
>>
>> http://www.groupstudy.com/list/CCIELab.html
>>
>>
>>
>>
>>
>>
>>
>>
>>
>>
>>
>>
>> Your Mail works best with the New Yahoo Optimized IE8. Get it NOW!
>> http://downloads.yahoo.com/in/internetexplorer/
>>
>>
>> Blogs and organic groups at http://www.ccie.net
>>
>> _____________________________________________________________________
>> __ Subscription information may be found at:
>> http://www.groupstudy.com/list/CCIELab.html
>>
>>
>>
>>
>>
>>
>>
>>
>
> ------------------------------
> The INTERNET now has a personality. YOURS! See your Yahoo!
> Homepage<http://in.rd.yahoo.com/tagline_yyi_1/*http://in..yahoo.com/
<http://in.rd.yahoo.com/tagline_yyi_1/*http:/in..yahoo.com/> >
> .
Blogs and organic groups at http://www.ccie.net
Received on Tue Jan 26 2010 - 13:07:53 ART
This archive was generated by hypermail 2.2.0 : Thu Feb 04 2010 - 20:28:42 ART