FlexVPN talk to sticks, PNDH redirection works not

I have a job FlexVPN Hub and spoke Setup and want to add feature talking-to-Spoke.

Unfortunately the hub does not seem to redirect traffic, that is to say PNDH does not work properly. I suspect "PNDH: reject addr type 0" the debug version tells me why it does not work. but I can't find any additional information about this message debgu.

When I trigger traffic since we talked to one subnet behind another spoke (in the example of 192.168.100/0/24) is not even an attempt to launch a session of encryption between the rays. All rays are configured the same.

Output of the PNDH during installation of the tunnel (hub site)

1544366: 14 Oct 12:58:55.790 it IS: % IKEV2-5-RECV_CONNECTION_REQUEST: received a request IKE_INIT_SA
1544367: 14 Oct 12:58:56.880 it IS: % LINEPROTO-5-UPDOWN: Line protocol on Interface virtual-access.3, state change downstairs
1544368: 14 Oct 12:58:56.881 CEST: PNDH: virtual-access.3: mode Tunnel last
"Uninitialized tunnel mode' to 'GRE on IPV4 point-to-point tunnel mode."
1544369: 14 Oct 12:58:56.881 CEST: PNDH: virtual-access.3: PNDH not activated
1544370: 14 Oct 12:58:56.882 CEST: PNDH: virtual-access.3: mode Tunnel last
"'ACCORD on point to IPV4 tunnel mode' to ' ESP (Encapsulating Security) to point 2 point IPv4 protocol used by the ipsec client.
1544371: 14 Oct 12:58:56.882 CEST: PNDH: virtual-access.3: PNDH not activated
1544372: 14 Oct 12:58:56.889 CEST: PNDH: reject addr type 0
1544373: 14 Oct 12:58:56.889 CEST: PNDH: addition of static maps to the cache
1544374: 14 Oct 12:58:56.889 CEST: PNDH: PNDH Redirect PI-code function initialized
1544375: 14 Oct 12:58:56.889 CEST: PNDH: redirect functionality initialized - platform attempt Init
1544376: 14 Oct 12:58:56.890 CEST: PNDH: reject addr type 0
1544377: 14 Oct 12:58:56.890 CEST: PNDH: reject addr type 0
1544378: 14 Oct 12:58:56.896 it IS: % IKEV2-5-SA_UP: SA PLACE
1544379: 14 Oct 12:58:56.896 it IS: % CRYPTO-5-IKEV2_SESSION_STATUS: tunnel Crypto v2 is in PLACE.  Peer : 500 f_vrf: i_vrf: Id:
1544380: 14 Oct 12:58:56.904 it IS: % LINEPROTO-5-UPDOWN: Line protocol on Interface virtual-access.3, changed State to
1544381: 14 Oct 12:58:56.905 CEST: PNDH: if_up: virtual-access.3 proto "NHRP_IPv4."
1544382: 14 Oct 12:58:56.906 CEST: PNDH: reject addr type 0
1544383: 14 Oct 12:58:56.906 CEST: PNDH: addition of static maps to the cache
1544384: 14 Oct 12:58:56.906 CEST: PNDH: impossible not to send registration - no configured NHSes
1544385: 14 Oct 12:58:57.905 CEST: PNDH: impossible not to send registration - no configured NHSes

PNDH debug output facility tunnel client site:

. 14 Oct 12:58:55.827: % FLEXVPN-6-FLEXVPN_CONNECTION_DOWN: FlexVPN (FLEXCLIENT) Client_public_addr = Server_public_addr =
. 14 Oct 12:58:57.067: % LINEPROTO-5-UPDOWN: Line protocol on Interface Tunnel0, changed State to
. 12:58:57.071 14 Oct: PNDH: if_up: Tunnel0 proto "NHRP_IPv4."
. 12:58:57.071 14 Oct: PNDH: reject addr type 0
. 12:58:57.071 14 Oct: PNDH: addition of static maps to the cache
. 12:58:57.071 14 Oct: PNDH: impossible not to send registration - no configured NHSes
. 14 Oct 12:58:57.079: % FLEXVPN-6-FLEXVPN_CONNECTION_UP: FlexVPN (FLEXCLIENT) Client_public_addr = Server_public_addr = Assigned_Tunnel_v4_addr = 10.255.176.15
. 12:58:58.071 14 Oct: PNDH: impossible not to send registration - no configured NHSes

The Hub config

Profile of crypto ikev2 EXTERN-IKEV2-PROFILE
fvrf game
match domain fqdn remote identity
identity local fqdn
authentication remote rsa - sig
authentication local rsa - sig
PKI trustpoint CA
DPD 10 2 periodic
list of cert group AAA RADIUS-PERMISSION name-mangler GET-FULL-HOST authorization
virtual-model 10

Crypto ipsec FLEXVPN-EXT-IPSEC-TEACHER profile
Set ikev2 EXTERN IKEV2-PROFILE

derived from Sho-config interface virtual-access 3
 
interface virtual-access.3
Description model Tunnel fuer VRF
VRF forwarding
IP 10.255.176.14 255.255.255.254
PNDH id network IP-5
the PNDH IP forwarding
source of tunnel
ipv4 ipsec tunnel mode

tunnel destination
tunnel path-mtu-discovery
tunnel vrf
Profile of tunnel FLEXVPN-EXT-IPSEC-TEACHER ipsec protection

No ipsec tunnel protection initiate
end

talking about the config

type of interface virtual-Template10 tunnel
Tunnel0 IP unnumbered
PNDH id network IP-5
intellectual property PNDH shortened virtual-model 10
ipv4 ipsec tunnel mode
Ipsec IPSEC-PROFILE of FLEXCLIENT protection tunnel profile
 
 
Ikev2 crypto FLEXCLIENT-PROFILE profile
identity match remote fqdn
match domain fqdn remote identity
identity local fqdn
authentication remote rsa - sig
authentication local rsa - sig
PKI trustpoint CA
DPD 10 2 periodic
AAA authorization list group cert Flex FlexClient-author
virtual-model 10

Crypto ipsec FLEXCLIENT-IPSEC-profile
the value of ikev2 FLEXCLIENT PROFILE

interface Tunnel0
Description [FlexHub Tunnel]
the negotiated IP address
PNDH id network IP-5
intellectual property PNDH shortened virtual-model 10
source of tunnel GigabitEthernet0
ipv4 ipsec tunnel mode
dynamic tunnel destination
Ipsec IPSEC-PROFILE of FLEXCLIENT protection tunnel profile
end

Tunnel work on hub site:

Tunnel-id Local Remote fvrf/ivrf status
1 500 500 READY
BA: AES - CBC, keysize: 256, PRF: SHA512, Hash: SHA512, DH Grp:5, Auth sign: RSA, Auth check: RSA
Duration of life/active: 86400/555 sec
ID of THIS: 18901, Session-id: 2086
Description of the State: made trading
Local spi: remote spi D13309864C08DB0E: 2098208B89845A8E
Local ID:
Remote ID:
Msg local req ID: id of msg req distance 55: 58
Local identificateursuivant msg: 55 remote following msg id: 58
Queue local req: 55 remote req queued: 58
The local window: 5 window distance: 5
DPD configured for 10 seconds, repeat 2
Unconfigured fragmentation.
Scope of authentication is not configured.
NAT - T is not detected
SGT Cisco Trust security is disabled
Assigned to host addr: 10.255.176.15
Initiator of SA: No.
Remote subnets:
10.255.176.15 255.255.255.255
10.255.18.44 255.255.255.255
192.168.100.0 255.255.255.0

tunnel work on the side with rays:

Tunnel-id Local Remote fvrf/ivrf status
1 500 500 no/no LOAN
BA: AES - CBC, keysize: 256, PRF: SHA512, Hash: SHA512, DH Grp:5, Auth sign: RSA, Auth check: RSA
Duration of life/active: 529/86400 sec
ID of THIS: 2029, Session id: 20
Description of the State: made trading
Local spi: remote spi 2098208B89845A8E: D13309864C08DB0E
Local ID:
Remote ID:
Msg local req ID: id of msg req distance 55: 52
Local identificateursuivant msg: 55 remote following msg id: 52
Queue local req: 55 remote req queued: 52
The local window: 5 window distance: 5
DPD configured for 10 seconds, repeat 2
Unconfigured fragmentation.
Scope of authentication is not configured.
NAT - T is not detected
SGT Cisco Trust security is disabled
Initiator of SA: Yes
Pushed to the IP address: 10.255.176.15
Remote subnets:
10.255.176.14 255.255.255.255
0.0.0.0 0.0.0.0

As already said - the flexVPn and encryption installation works fine - with the exception of the PNDH redirection feature.  Any help with this would be appreciated.

ipv4 ipsec tunnel mode<--- nhrp="" in="" ip="" world,="" may="" not="" work ...=""  try="" with="" gre?="" nhrp="" in="" ip="" world,="" may="" not="" work ...=""  try="" with="">

1544368: 14 Oct 12:58:56.881 CEST: PNDH: virtual-access.3: mode Tunnel last
'Uninitialized tunnel mode' to 'GRE on the IPV4 tunnel mode to '
1544369: 14 Oct 12:58:56.881 CEST: PNDH: virtual-access.3: PNDH not enabled

type of interface virtual-Template10 tunnel
Tunnel0 IP unnumbered<--- why="" tunnel="" 0="" and="" not="" the="">

Configuration of SAMBA?

Tags: Cisco Security

Similar Questions

  • Printer redirection does not work in vWorkspace 8.0

    Hi all

    I am facing problem of printer redirection in Windows 2003 TS.

    When I try to connect via RDP, then the local computer printer redirection works very well.

    But when I connect Server Terminal Server via url web vworkspace then the printer is not redirection. It does not show in the printer and the camera.

    Pease help me solve this problem.

    We use vWorkspace 8.0 and windows server 2003 as a Terminal server server.

    Thank you

    Jean Claude

    Redirect has not been activated.

  • MIC not working not not with voice recognition or Siri in texting

    iPhone 6 - 9.2.1 firmware - the mic input does not provide a valid signal to Siri, or dictation in the Messages. It * is * work very well for the new application of musical note, which would indicate that the equipment is not broken.

    In Siri or Messages, the erratic noise signal indicator shows, while in fact, there is no entry and do not change or respond when it * is * talk.

    It still does not. Reset all settings, change 9.3.1 update... No..  Microphone only works in the voice and music notes. Does not work in the Siri, Messages or Google.  One thing to note is that it works with the Apple ear buds mic.   You would think that there must be a problem with the hardware with the microphone, but the microphone * fact * works in voice memos or notes of music... so that the theory does not take place.

  • MIC not working not not his suddenly

    Well, today, before I used microphone on Skype, and when im trying to talk with my friend MIC will not work. Why, what has happened, everything I did I wasn't on the computer for everything. MIC do not work in any application... What is the problem, I tried to install Realtek HD drivers once again, the port on rear panel for mic, mic in front place and does not. My PC is HP P6-2010scm with Windows 7 Professional.

    http://i5.aijaa.com/b/00151/10817377.jpg

    What could be wrong?

    E: even different microphones won't work. I think that it is a sound card problem

    Hi, it is probably a failure of mic, it did not work even on the other pc, and I bought a USB microphone that works well

  • (Redirected) Order not received and Dell could not be contacted

    I was due to take delivery of my laptop today and follow-up mail forward. Then, I received an e-mail saying that a delivery attempt had been filed and a card left through the box to the letters. No hardened as I have at home all day working in a lounge overlooking on the road; No vehicle courier and no card left through the door. I tried unsuccessfully to contact the courier service, but their automated system has no tree installation pointing out problems like mine and you can not email. So I tried to contact Dell and it was just as unsuccessful that you need all kinds of delivery codes and tastes. You can't really talk to anyone and Dell seems not to care about that. Finally, I used the online chat and left messages but I do not hold much hope. I'm now about £800 small and nobody seems to care. So much for the customer service.

    Anyone else had problems similar, if yes, how did you deal with it?

    Hi Churchward 25,

    You can transfer this in forum customer care for assistance.

    http://en.community.Dell.com/support-forums/customercare/#pi40817=1

  • USB redirection works with a view Windows Client that connects to a Pool of RDS running Server R2 2012

    I installed the Agent view Horizon (6.0.0) and direct view connection Plugin (6.0.0) on a physical server running Windows Server R2 2012 with desktop Services remotely active.  I would use the USB redirection from the client to the server.   When I connect to the remote desktop session by using the Windows Vista client, he tells me that the USB redirection is disabled.   I tried connecting the View Client to the server view connection and directly to the RDS Server with the same result.  I need to activate RemoteFX on the Windows Server running RDS for USB redirection to work?  I don't have any hardware remotefx, that's why I have not yet tried.

    USB redirection is not supported on the RDS (2008 or 2012) guests in Horizon 6.0.

    see you soon

    peterB

  • Layout phone redirection does not - built and hosted on Muse

    Hello

    I just added as a Tablet and phone to my Muse built office layout. The redirect works fine for the Tablet, but the desktop version happens on my smartphone (Android Moto X). The Web page is http://www.elegantperfection.com/ that I am hosting with Adobe so I struck just publish - I do not use to publish to FTP. The settings in the properties of the site are to redirect; not sure if there is another step, but it seems to work fine for the tablet. Any ideas as to why the redirect does not work? Thank you!

    Hello

    I see that you published the Business catalyst site, in this case, could you please try to re - publish the entire site again, and check if that helps?

  • Muse on BC - URL list site redirects does not

    Hello. A Muse site just disappeared live on host BC.

    URL redirects don't seem to work.

    Do a Google search on "parkerandassociates.co.nz Amy Williamson" gives a result from the screenshot below shows the redirect that it should work, but in reality, the page is not be found at http://www.parkerandassociates.co.nz/people/amy-williamson/ . I tried several times to change the Action and also imported the Import URL redirection method and it imported successfully.

    My import file was CSV and had a line for the following columns old Url compound (= / people/amy-williamson /) new URL (/ amy - williamson.html) enabled (True). I wasn't sure what to put in the column for Enabled, so I put "True", as shown below. But still the redirection does not work.

    Can someone tell me where I go wrong?

    See you soon

    Grant

    urlRedirects.jpg

    Hi Grant Senior,

    Update the source of redirection of/people/amy-williamson / to /people/amy-williamson/index.html and the http://www.parkerandassociates.co.nz/people/amy-williamson/ URL should then redirect successfully. It's because BC sees the source in a directory and not a real page.

    I've done this for http://www.parkerandassociates.co.nz/people/amy-williamson/ in your name and can confirm that it works now.

    See you soon.

  • Since the update with OS 10.11.6, flash not working not properly

    Just got a new Mac Book Pro, new on mac in general. Had a video to play on a Web site but didn't work not, downloaded Chrome, worked well. Then made the update to OS 10.11.6 (not), and the video does not work (it says: cannot load the Flash plug-in). Made sure plugin has been enabled in my Chrome. Tried to download Flash himself, tried to remove Chrome and Flash and download Chrome still once, nothing works. Now for some reason, it works... What is (and was) happening... Someone has an idea? THX!

    -Chrome has built in Flash.

    -Safari does not come with Flash and use Flash with Safari, you need to download and install Flash

    So this is why worked chrome and Safari worked after downloading and installing Flash. Make sure you just threw always get Flash from the Adobe website.  Once you install Flash from Adobe it has also installed a Flash preferences panel in system preferences and yo can update Flash from here

  • iPhone upgrade of the navigation software now works not properly

    iPhone 5

    New IOS software updated and now the navigation screen not working not properly

    is your site on?

  • IOS 9.3.2 whatsapp works not

    IOS 9.3.2 whatsapp works not

    pls help

  • Some web features working not (buttons, drop-down menus, etc.)

    I have recently reinstalled windows 7 on my machine, and since I had problems with firefox. I had the same exact configuration installation and firefox before reinstall as far as I can remember, and I've not had the problem then. I tried the current version and the beta version of firefox.

    Basically, on some Web sites, there are some things that does not work as it should. Some buttons does nothing, some drop-down menu nothing done, image resizing works not etc.. Maybe it has something to do with javascript? Although most of the javascripts appears.

    Here's an example: on this site: http://www.bitcoinx.com/profit/
    'Reset' and 'Calculate' blue buttons does not work. The effect of the passage of the mouse works, but when I click on them, absolutely nothing happens.

    Rather a general answer I'm afraid, because I don't see an obvious problem & solution:

    1. Note for any problems with the sites that it is always worth to erase cookies from this site and to cache How to clear Firefox cache &delete cookies to remove the information from Web sites is stored on your computer
    2. Try in safe mode (see questions to troubleshoot Firefox in Safe Mode) that is accessible from your Firefox Button. (but at this stage try not yet reset)
    3. If the above does not help then try the Firefox reset, but be aware, you will lose the open tabs, extensions and preferences, you may need to favorite things first if you can find them still see Firefox Refresh - reset the settings and Add-ons
  • My Apple iPhone 5 touchscreen doesn't work not when the call comes. This problem is only in locked mode and mode unlocked when the call come it works normally. The problem is only locked Iphone and a just coming guard time. give soltn

    Hello can anyone give solution to my problem.

    my iPhone touch 5 works not when it is in locked mode and it's time all incoming call came the touch works do not. other times, the touch works normally wat is the problem. ?

    If you disturb not activated. Settings > do not disturb.

  • Keyboard and mouse not working not

    Keyboard and mouse not working not
    I tried to use the method of matching and again, it won't work. What should I do? Devastated and frustrated

    The same problem. Qosmio all in one PC. Also tried the instructions for pairing and the light indicates successful pairing but mouse and keyboard still does not. Can someone help please...

  • Satellite C660-115 - error message "Gfxui works not" at startup

    I got a Toshiba Satellite C660-115 Windows 7 and at startup I get the message ' gfxui works not ", can I ignore what my laptop seems to work ok.

    It is a problem with the GUI GUI Intel.
    You need to reinstall the Intel graphics driver.

    Visit the page of the Toshiba UE driver and download and save the correct Intel driver

Maybe you are looking for

  • Bent corner trackpad

    Last week, I bought a new Macbook Pro. I noticed that one of the corners of the trackpad is protruding outward. Specifically, its case is slightly down at this point. Apple service could do something about it? In all other respects, my Macbook works

  • HP service plugin - A5-sized paper

    Based on the advice of erico, I can connect my officejet hp 6700 to my nexus 7. However, when I try to print a word with an A5 page layout document, it only print on 50% of a page A5. I tried all size available on the plugin page (4 x 6 inches, 5x7in

  • Network of comments Airport Extreme (7.7.3) has stopped working

    Our network of comments Airport Extreme (7.7.3) has stopped working.  We moved offices and even if my MacBook Air (13-inch mid-2013, El Capitan 10.11.3) can see the two networks, the option of comments does not connect to internet at all.  I did a re

  • Plug &amp; Play does not work - cell HP Pavilion dm4 - Windows 7

    These three issues all occurred as soon as I uninstalled Norton (demo of limited duration which came with my PC) and installed AVG. I think they are all symptoms of the same underlying issue. 1. the popup saying "no amd graphics driver is installed o

  • DONGLE USB DVB - T is not recognized after 5 minutes of use.

    mo_941 Hello Lady/sir I'm mo_941. I have a problem with my laptop Information for PC: computer toshiba laptop Model name: Satellite M115 S3094 OS version: Microsoft Windows XP Professional 5.1.2600 Service Pack 3 When I installed the device (DVB - T