Jump to content

akosijonel

Members
  • Content Count

    142
  • Joined

  • Last visited

Community Reputation

5 Neutral

About akosijonel

  • Rank
    Advanced Member

Profile Information

  • Gender
    Male
  1. Hi Guys, I am currently running UNL in google cloud. I have the following topology and configuration XRV1 0/0/0/1 --------------0/0/0/1 XRV2 xrv1 int gi0/0/01 ipv4 address 192.168.1.1/24 no shutdown xrv2 int gi0/0/01 ipv4 address 192.168.1.2/24 no shutdown I am unable to ping both sides. Below is the debug ipv4 packet output RP/0/0/CPU0:Aug 8 17:15:56.088 : ipv4_io[267]: : source 192.168.1.2 (local) dest 192.168.1.2, pak: 0xb0c07f47, vrf 0x60000000, tbl 0xe0000000 RP/0/0/CPU0:Aug 8 17:15:56.088 : ipv4_io[267]: Sending to netio RP/0/0/CPU0:Aug 8 17:15:56.088 : ipv4_io[267]: : source 192.168.1.2 (local) dest 192.168.1.2, pak: 0xb0c07d7b, vrf 0x60000000, tbl 0xe0000000 RP/0/0/CPU0:Aug 8 17:15:59.808 : ipv4_io[267]: Sending to netio RP/0/0/CPU0:Aug 8 17:15:59.808 : ipv4_io[267]: : source 192.168.1.2 (local) dest 192.168.1.1, pak: 0xb0c07f47, vrf 0x60000000, tbl 0xe0000000 RP/0/0/CPU0:Aug 8 17:16:01.828 : ipv4_io[267]: Sending to netio RP/0/0/CPU0:Aug 8 17:16:01.828 : ipv4_io[267]: : source 192.168.1.2 (local) dest 192.168.1.1, pak: 0xb0c07f47, vrf 0x60000000, tbl 0xe0000000 RP/0/0/CPU0:Aug 8 17:16:03.848 : ipv4_io[267]: Sending to netio RP/0/0/CPU0:Aug 8 17:16:03.848 : ipv4_io[267]: : source 192.168.1.2 (local) dest 192.168.1.1, pak: 0xb0c07f47, vrf 0x60000000, tbl 0xe0000000 RP/0/0/CPU0:Aug 8 17:16:05.868 : ipv4_io[267]: Sending to netio RP/0/0/CPU0:Aug 8 17:16:05.868 : ipv4_io[267]: : source 192.168.1.2 (local) dest 192.168.1.1, pak: 0xb0c07f47, vrf 0x60000000, tbl 0xe0000000 RP/0/0/CPU0:Aug 8 17:16:07.887 : ipv4_io[267]: Sending to netio RP/0/0/CPU0:Aug 8 17:16:07.887 : ipv4_io[267]: : source 192.168.1.2 (local) dest 192.168.1.1, pak: 0xb0c07f47, vrf 0x60000000, tbl 0xe0000000
  2. [Hidden Content] Thank you very much
  3. You NBMA address is somehow advertise in the IGP running in your DMVPN network. Ansari? are you from RACE TO CCIE Group?
  4. Hi MarkMark - Was Crypto already applied on your configuration when that happened? Did you check show crypto isakmp sa? and show crypto ipsec sa?
  5. This is fake. this is from K7/K8 from before......
  6. Hi All, Is there any document for the order of operation for DMVPN with IPSEC like this document? Inside-to-Outside Outside-to-Inside If IPSec then check input access list decryption – for CET (Cisco Encryption Technology) or IPSec check input access list check input rate limits input accounting policy routing routing redirect to web cache NAT inside to outside (local to global translation) crypto (check map and mark for encryption) check output access list inspect (Context-based Access Control (CBAC)) TCP intercept encryption Queueing If IPSec then check input access list decryption – for CET or IPSec check input access list check input rate limits input accounting NAT outside to inside (global to local translation) policy routing routing redirect to web cache crypto (check map and mark for encryption) check output access list inspect CBAC TCP intercept encryption Queueing
  7. Hi, Sorry about this question but may I ask what debug did you use to troubleshoot this ticket?
  8. Question based on guru2010's post Assume that there is a server located in OSPF Area 1 on the link between R21 and R22 in the Global Service Provider Network. The NOC team has identified that the traffic that originates in OSPF Area 0 and destined to this server is not load balanced by R1. Fix the so that R1 traffic be can load balanced as shown in output: R1#traceroute 134.56.78.49 Type escape sequence to abort. Tracing the route to 134.56.78.49 VRF info: (vrf in name/id, vrf out name/id) 1 123.45.67.6 [MPLS: Label 26 Exp 0] 1 msec 123.45.67.18 [MPLS: Label 20 Exp 0] 0 msec 123.45.67.6 [MPLS: Label 26 Exp 0] 0 msec 123.45.67.42 1 msec 123.45.67.38 0 msec * Faults 1. IP OSPF COST R22 - Solve by changing the cost 2. Inbound Access List in R3 - Adding DSCP 6 for routing 3. Cannot Traceroute 134.56.78.49 - Not yet solved Please comment below
  9. Hi, I am not able to ping from R1 to the address.
  10. You should try it first. ^___^)/
  11. I Tried to solve this and I got this 1. Change ip access-group 10 in to ip access-group 10 out or 2. Create a route-map on R21 and R22 route-map DSCP set ip precedence routine ip local-policy route-map DSCP but I am still figuring out the best way to answer.
  12. Thanks a lot. I am currently polishing my configs just in case I miss something.
  13. Sorry but I dont get it. Is it possible for you to explain more. Thanks in advance. In the workbook that I am using it says that i need to have 5 123.45.67.38 msec 123.45.67.42 0 msec 123.45.67.38 0 msec but when I lab it I get this 5 123.45.67.42 2 msec 123.45.67.38 0 msec 123.45.67.42 0 msec
×
×
  • Create New...