invalid-spi-recovery crypto isakmp command worked well in the case of DMVPN

Hello

I did the Setup for Hub/spoke in th DMVPN case and it worked fine. But after reloading Hub and I saw an output of error below, well I added the command invalid-spi-recovery isakmp crypto in the Hub & spokes:

* 7 Oct 03:10:03.175: CRYPTO-4-RECVD_PKT_INV_SPI %: decaps: rec would be package IPSEC a bad spi to destaddr = 150.1.1.1, prot = 50, spi = 0 x 72662541 (1919296833), port = 150.3.1.3

* 7 Oct 03:10:03.175: CRYPTO-4-RECVD_PKT_INV_SPI %: decaps: rec would be package IPSEC a bad spi to destaddr = 150.1.1.1, prot = 50, spi = 0 x 72662541 (1919296833), port = 150.2.1.2

Note: spoke1 IP address: 150.2.1.2/spoke2's IP address:150.3.1.3/Hub's IP address: 150.1.1.1

My temporary solution for the same problem, I need to erase SPI by manually and it worked fine again.

Everyone has the same problem, please let me know

Kind regards

TRAN

Hello

There is a common misconception of what the invalid-spi-recovery crypto isakmp command does. Even without this command IOS already performs a kind of recovery invalid SPI feature by sending a DELETION notify for the SA has received send peer If she already has an IKE SA with this peer. Still once, this happens regardless of whether the order invalid-spi-recovery crypto isakmp is enabled or not.

With the order of isakmp crypto invalid-spi-recovery , he tries to regulate the condition where a router receives the IPSec traffic with invalid SPI and

It doesn't have an IKE SA with this peer. In this case, it will try to put in place a new IKE session with the peer and then send a DELETION notification on the newly created HIS IKE. However, this command does not work in all configurations of crypto. Are the only configurations that this command works cryptographic instantiated, for example, Asit, and peer static maps from static cryptographic cards where the peer is defined explicitly. Here is a summary of commonly used configurations of crypto and know if invalid spi recovery works with this configuration or not:

Crypto config Not valid-spi-recovery?
Static crypto map YES
Dynamic crypto map NO.
P2P GRE with TP YES
using love TP w / static PNDH mapping YES
using love TP w / dynamic PNDH mapping NO.
ASIT YES
EzVPN client N/A

For help with your scenario, you can enable DPD (isakmp crypto keepalive) on the shelf to help the recovery tunnel.

Thank you

Wen

Tags: Cisco Security

Similar Questions

  • DMVPN with invalid SPI recovery / DPD

    Dear Experts,

    I'm evaluating a networks of average design company DMVPN Phase 2 scope, trying to optimize the time of receovery after a failure and restoration of a DMVPN counterpart.

    1. I just spent through a PDF of Cisco Live at a workshop of 2011 named "Advanced Concepts of DMVPN - BRK 4052".

    It is said (without further explanation) that the invalid SPI recovery feature is not useful with DMVPN.

    Can anyone explain, why?

    2 DMVPN involves the use of the Tunnel (TP) Protection. I read the reviews that say that you can not use Dead Peer Detection (DPD) as well as the TP.

    Unlike these reviews, Cisco DMVPN V1.1 design guide recommends a configuration container:

    ISAKMP crypto keepalive 10

    That means, I have to use DPD, but without "periodicals" KeepAlive? If so, could you explain?

    Thank you very much!

    Dear Sebastian,

    1 SPI recovery means essentially that the answering router must meet the same initiator VPN router if the SPI was invalid, the response of the intervener would be an 'invalid' error to the initiator VPN.

    Why it is not recommended for DMVPN?

    Well, according to the previous description of SPI, imagine if someone upsets your router with rogue applications! with the resumption of active SPI, it means that your router would need to respond to all messages which he received with the message "Invalid Error", which basically means--> attack (Denial of Service Attack) back--> high CPU processing on your router.

    http://www.Cisco.com/en/us/docs/iOS/12_3t/12_3t2/feature/guide/gt_ispir.html#wp1045200

    How is it that relates to DMVPN?

    Well! DMVPN is mainly deployed with large number of rays! and even if no one attacks you! your rays can attack you

    2. I don't think that having periodic KeepAlive is what we hear in the comments on demand or periodic KeepAlive is not really effect DMVPN.

    I don't know what are the comments you've read, but I think you can use DPD! There have been some incompatabilites filed for tunnel KeepAlive, but as far as I know, nothing major was filed against ISAKMP KeepAlive.

    HTH!

    AMatahen

  • The speaker volume in the computer sound control mixer is up and works well with the speakers, but with headphones, I can hardly hear.

    Original title: the headphone volume

    How can I activate the volume for headphones? the speaker volume in the computer sound control mixer is up and works well with the speakers, but with the headdphones that I can barely hear

    Hello
     
    1. who is the operating system installed on the computer?
    2. What is the brand and model of headphones?
    3A this works much earlier?
    4. What is the brand and model of the sound card?
    5. have you ever tried to play the Audio using different media player applications and check?
    6. have you tried to connect the headset to another computer or phone and check if it works well?
     
    I suggest you follow these methods and check.
    Method 1: Run the audio troubleshooter.
     
    Method 2: Set the earpiece/microphone as default device and check.
     
    a. right click on the volume icon in the system tray at the right corner on the desktop.
    b. Select the playback device, go to torecording tab.
    c. make a right click and headphone/microphone as the default device.
    d. click on apply and ok.
     
    If above steps fails, proceed to method 3.
     
    Method 3: I suggest to disable the improvements and check.
     
    a. right-click on the icon "speaker" at the bottom right of the screen.
    b. Select "playback devices".
    c. right-click on the helmet.
    d. Select Properties
    e. click improvements
    f. check Disable all improvements
    g. click OK
     
    You can read this article for more information:
     
    Tips for solving common audio problems

    You can also contact the manufacturer of headphones and check.
     
    I hope this helps!
  • My desktop version of my site works well but the mobile and tablet versions have any overlap and the entire page. If I can't pin things that it stops?

    My desktop version of my site works well but the mobile and tablet versions have any overlap and the entire page. If I can't pin things that it stops?

    Hi Pedro,

    Make sure that when you design the phone and tablet version to keep in mind the limits of dimensions.

    Please share the url of your site for further analysis.

    Kind regards

    Akshay

  • Hi hope someone can help? I have acrobat pro, 6 have worked well for the past two years but then just stopped working. Have reinstalled but still won't open, ronning windows 7. Help please!

    Hi hope someone can help? I have acrobat pro, 6 have worked well for the past two years but then just stopped working. Have reinstalled but still won't open, ronning windows 7. Help please!  Janice

    Hey janicem42177174,

    Adobe does most support the installation and use of Acrobat 6 because it is a very old version that is not compatible with Windows 7.

    I suggest you to please use the latest version of Acrobat 11.0.10 is perfectly compatible with your operating system with its functions and improved functions.

    You can download a free trial version of 30 days of Acrobat from here:

    Download Adobe Acrobat free trial | Acrobat Professional XI

    Let me know how it goes

    Kind regards

    Ana Maria

  • Why the CC lightroom does not recognize my users folder when you try to import?  I can not imaport images in the program.  It has worked well in the past

    Why the CC lightroom does not recognize my users folder when you try to import?  I can not imaport images in the program.  It has worked well in the past

    It is an Apple problem. They obviously fixed with a change to iTunes. Download the update on their part.

    HAL

  • Feather of apple works well with the iPad air2

    I would use a pen to take notes and ratings on Adobe reader etc. will be (or is) the pen of Apple works well with iPad air2?

    # Apple pencil is only compatible with the iPad Pro.

  • Satellite L650 doesn't work well after the BIOS 2.40 update

    Hello

    I have a L650 Psk1je yesterday, I updated my bios to 2.20 to 2.40 and since then my laptop does not work well
    can someone tell me please how to downgrade my bios to 2.20 again

    Thank you

    Downgrade BIOS can be done using only a traditional BIOS version
    These versions are not available for download.
    You can download only the latest BIOS based victory.

    But why do you say that it is not working properly?
    What s wrong?

  • Z: Xperia music app works well after the update of Lollipop

    Hi, the music app does not work well after that I update my phone to Lollipop, the art of the album are lost and the music info is confusing. I tried to add album art and change the news of music as well, but after some time, the problem comes back again. Can anyone help please?

    -Go to settings-> Apps-> all-> music-> stop Force, uninstall updates, clear data and restart your phone.

    -Go to the game and re store - update your music application.

  • What size, type and brand of SSHD fits and works well in the caddy in E6410?

    Hello

    I just got my laptop E6410 a caddy, who works with SATA drives. As I wish to expand my storage saying up to 1 TB with the caddy, I don't know what type, size, brand of SSHD 1 TB would fit into the caddy and work well in my laptop E6410?

    Suggestions are really appreciated.

    Concerning

    Endre

    It probably uses a 2.5 drive "-check with the provider of caddy."  It will certainly require a drive of 7 mm and can take a 9.5 mm as well.

    There are three manufacturers of drives - WD (HGST), Seagate (Samsung) and Toshiba.  They will all work.

  • Application failed (MFC) in the release through the optimization of the compiler, but works well in the debug version

    I am facing problem with the Release version. Application works fine in the Debug version, but in the Release version a pointer initialized to contain the object of another class becomes allocation to different addresses, causing corruption to its values.

    My main application class is K32App
    code in K32App.h file
    CSheetPrintManager* m_pSheetPrintManager;
    CSheetPrintManager* GetSheetPrintManager() { return m_pSheetPrintManager; }
    
    In file K32App.cpp
    K32App::K32App()
    {
      m_pSheetPrintManager= NULL;
    }
    BOOL K32App::InitInstance()
    {
      if(!m_pSheetPrintManager)
        m_pSheetPrintManager= new CSheetPrintManager();
    }
    K32App::~K32App()
    {
      if(m_pSheetPrintManager)
        delete(m_pSheetPrintManager)
    }
    
     In my file  CSheetPrintManager.cpp
     void CSheetPrintManager::CSheetPrintManager()
     {
       //Initialized all member variables to default values.
       Init();
    
     }
     void CSheetPrintManager::Init()
     {
       m_nSheetType = SheetIllegalNone;  //long
       m_sBankEntry.Empty();         //CString
       m_bHistorical = FALSE;        //BOOL
       m_bDebitDetailsSet = FALSE;  //BOOL
       m_mapRequested.RemoveAll(); // Type CMap
     }
    

    During the startup of the application, when it reaches

      if(!m_pSheetPrintManager)
        CSheetPrintManager= new CSheetPrintManager();
    

    and trying to create a m_pSheetPrintManager object, a 'this' inside the CSheetPrintManager.cpp pointer shows a valid address (0x03768ce0) at the stop just to brace {, once I more in CSheetPrintManager.Init (), not 'this' gets different location and starting point to a different address (0 x 0000000) and then passing more its starting pointing to an another rental (0x03786ce0)} ", then arriving to m_mapRequested.RemoveAll(); 'this' points to some other location. back to main application C32App.cpp file I get next to 'm_pSheetPrintManager' error CXX0030 ' expression cannot be evaluated" in the window of the car. and application continues to run. See what get when move mouse m_pSheetPrintManager (can't post the image because need 10 reputation for him :) so antisocial)Auto window studio screenshot 

    In debug mode, I get m_pSheetPrintManager pointing to the same location during all the processing of the application and members are always correctly initialized.

    But in Release mode, m_pSheetPrintManager continues to point to the different location (address in the window of Auto value). and all the class member variables CSheetPrintManager garbage (Uninitialized) values with each line of treatment within the CSheetPrintManager class.

    If I disable the optimization of the c++ in Release Mode then it works very well without any problems.

    Any help/advice/suggestion is the most popular. Thanks in advance.

    PS: This is my first question here so please excuse if you lack something to point or express properly.

    This issue is beyond the scope of this site (for consumers) and to be sure, you get the best (and fastest) reply, we have to ask either on Technet (for IT Pro) or MSDN (for developers)
    *
  • New type of font "Century Gothic" and works well with the 'live view', but also a google chrome. As soon as I download my index.html file my changes disappear and always see them in dreamweaver, but not on my real Web site. any help will be great. Thank y

    I downloaded my new "Century Gothic" font type and works well with live view, but also a google chrome. As soon as I download my index.html file my changes disappear and always see them in dreamweaver, but not on my real Web site. any help will be great. Thank you!

    I use and Filezilla to connect to our FTP site.

    I see on line 42 of style.css

    do-family: 'Courier New', Courier, monospace;

    I see on line 180

    do-family: "Helvetica Neue", Helvetica, Arial, sans-serif;

    and I see FontAwesome used in several places.

    I can only conclude that Courier New is the applied font.

    If you have a different version of style.css on your local system?

  • Adobe Premiere Pro and After Effects works well with the merger?

    Hey everybody,

    I'm in the middle of a semester at the University and I use Adobe Premiere Pro and Adobe After Effects (Windows version). I was wondering if the merger would work well with these programs? I intend to the latest update of merger next week.

    The mac I use is an iMac in August 2008 (running 10.5.6). 3.06 Ghz, 4 GB RAM, 1 TB HD, and a Nvidia GeForce 8800. I also install Windows XP Pro edition and the value of using two processors and 2-3 GB of RAM.

    I will also put it on a new account make sure that practically nothing is running while im current merger.

    I use this for my final college.

    Edit: I forgot to mention. I use CS3. My school has not yet updated in CS4.

    In addition, you think that a 64-bit version of Vista will work best and then 32 bit XP on this partition?

    I love Fusion as much as anyone here and use it a lot. But, in saying that...

    You use this something really important - your final college. You need to perform at its best performance with as few problems as possible because you don't have a lot of time in your semester left (in the grand scheme of things).

    My advice - do not experiment. Work around the merger (as heretical as it may seem on this forum) and first and AfterEffects in a punt in native mode Windows XP OS that is on a BootCamp partition. Video editing will focus on i/o and graphics of your system performance - and nothing works better for this than the native access to the system.

    Running two processors in a virtual merger with computer on a machine with 2 hearts can lead to better performance and is not recommended.

  • Works well in the preview of Flash, but not when the server!

    OK my Flash animation tests and works well on I publish Preview in Flash, but when I upload it to the server it does not work as it is supposed to. is there a way to debug or trace what happens while it is running?

    Details:

    I have 113 tcname_1 of dynamic text-> tcname_113 field names

    I have 113 buttons named button_1-> button_113

    The dynamic text boxes get their data to a file named trees1.txt

    I tried to change three of the text boxes to use device fonts, but has not made a difference

    Here is my code AC3:

    Links button: all the buttons to open in iframe "tdes.

    link en button number

    I have 113 buttons.

    for (var i: int = 1; i < = 130; i ++) {}

    {if (this ["button_" + i])}

    This ["button_" + i] .addEventListener (MouseEvent.Click, f);

    }

    }

    function f(e:MouseEvent):void {}

    var n: String = e.currentTarget.name.split ("_") [1];

    navigateToURL (new URLRequest("ranch.php?id="+n), "tdes");

    }

    end of the links button

    Create the instance of URLLOader

    var myLoader:URLLoader = new URLLoader()

    the data will come as URL-encoded variables

    myLoader.dataFormat = pouvez

    Load using a URLRequest, same local beeing

    myLoader.load (new URLRequest ("trees1.txt"))

    listener onLoad handler

    myLoader.addEventListener (Event.COMPLETE, onDataLoad)

    Error handling

    myLoader.addEventListener (IOErrorEvent.IO_ERROR, onIOError)

    myLoader.addEventListener (SecurityErrorEvent.SECURITY_ERROR, onSecurityError)

    Could be an error or a message

    myLoader.addEventListener (HTTPStatusEvent.HTTP_STATUS, onHTTPStatus)

    Add a listener for the complete event

    function onDataLoad(evt:Event) {}

    trace (evt. Target.Data.cant);

    for (var i: uint = 1; i < evt.target.data.cant; i ++) {}

    This ["tcname_" + i] .text = evt.target.data ["tcname_" + i]

    This ["tcname_" + i] .visible = false;

    This ["button_" + i] .addEventListener (MouseEvent.ROLL_OVER, buttonover);

    This ["button_" + i] .addEventListener (MouseEvent.ROLL_OUT, buttonout);

    trace (i);

    }

    }

    ON working CAPITAL make the visible text field and change color

    function buttonover(e:Event) {}

    var tf:TextField = TextField (this ["tcname_" + e.currentTarget.name.split ("_") [1]]);

    trace (tf.name);

    TF. Visible = true;

    tf.textColor = 0xff0000;

    }

    MAKE working capital change color and make invisible

    function buttonout(e:Event) {}

    var tf:TextField = TextField (this ["tcname_" + e.currentTarget.name.split ("_") [1]]);

    tf.textColor = 0 x 000000;

    TF. Visible = false;

    }

    reminders of the error

    function onIOError(evt:IOErrorEvent) {}

    trace ("IOError:" + evt.text)

    }

    function onHTTPStatus(evt:HTTPStatusEvent) {}

    trace ("HTTPStatus:" + evt.status)

    }

    function onSecurityError(evt:SecurityErrorEvent) {}

    trace ("SecurityError:" + evt.text)

    }

    again is it works fine when publish Preview in Flash, but not on the server. the text does not show the server when I hover over the buttons!

    You can see that to:

    www.myblueranch.com/index2.html

    Do you notice something that I did wrong? is it possible to debug while on the server?

    Thank you very much.

    Layth

    When I see her in IE8 and Firefox 3.6.8 I see text, although in Firefox the text sometimes does not appear.  But I attribute not this program does not, but even more to what appears to be insufficiently size textfields.  What you need to do is set the property to autoSize to the textfields.

    I created a movieclip that contains the button and the textfield and use that instead of 113 separate instances of both.

    In all cases, you should be able to get the Flash debug player so that you can see this error occur during playback in the browser (http://www.adobe.com/support/flashplayer/downloads.html).  Although you won't find may not be any errors, fair textfields that are not the big enugh to display their text.

  • When I click the + to the right of the last tab, nothing happens. When I press Ctrl T, nothing happens. This just started today. Until today, these commands worked well.

    For some reason, Firefox won't open a new tab. It happens on my desktop and my laptop. I noticed this problem today, but have never had a problem until this point. I can't imagine what I did differently to my computer.

    You are welcome. Please mark this as RESOLVED issue.

Maybe you are looking for

  • Panel Test DAQ opened on the remote system

    Using the command-line tool nidmfpan.exe you open a test panel to a device on your system by specifying its name.  Here is an article which he described. http://digital.NI.com/public.nsf/allkb/9B628A8B1B13136F86256DDB0004DE4D But what is not mentione

  • High processor for messenger

    Messenger uses the processor on my pc what can I do about it

  • How to fix a 404 with craigslist.austin tx

    I ADVERTISE ON CRAIGSLSIT AUSTIN, TX... HOWEVER, FOR SOME REASON ANY (LATELY), I CAN'T DO MY POST TO POST... CONTINOUSLY DISPLAY SAYS NO VALID ID #, OR 404 ERROR. Help, please. DON

  • Playing albums rather than individual songs

    As a newbie pathetically of new, I can't understand how to select an entire album to play. When I click on an album, I get a list of the songs of your choice - but I want to play the entire album. I know it's beyond obvious, but someone, have mercy o

  • Remote Desktop connection - how do you find the databases

    Objective: see Web site and code that someone has written/produced in ASPX.NET and MS SQL Server 2008 database. The reason is that, the website and the database need some changes (to be able to do that, I also know the names of tables-> SQL-> databas