DMVPN hub & spoke topology; latest 12.3T IOS releases
1. test hub powered up
2. test spoke powered up
3. IPSEC GRE tunnel establishes
4. NHRP information exchanged
5. EIGRP adjacency established
6. hub powered off
7. EIGRP adjacancey lost as expected
8. hub powered back up
9. EIGRP adjacency is not re-restablish
10. spoke sends NHRP registration packet at 60 second intervals
11. hub discards NHRP packet with message
" %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid
spi for destaddr=, prot=50, spi=0xA0B93D34(2696494388),
srcaddr= "
issuing the command clear cry session or power cycling the spoke
allows EIGRP adjacency to be re-established
a) has anyonne encountered this type of porblem with DMVPN ???
b) any viable solutions or workaround ???
Hi Merv!
Had the same issue as you and under the same circumstances. I found this link on Cisco's website that deals with this issue on the 12.3T releases and will explain it better than I could.
formatting link
Worked for me but does take a few minutes to renegotiate the security associations.
Thanks for the response.
What i did late yesterday was to configure lifetimes for the ISAKMP and IPSAEC SA's on the spoke and that seemed to do the trick.
The Cisco document you pointed me to is excellent and spot on for my issue.
Thanks again for taking the time to respond.
