Cisco Cisco 1800 2800 3800 2-Port Fast Ethernet High-speed WIC
© 2014 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information.
Page 28 of 63
ip nhrp cache non-authoritative
tunnel source GigabitEthernet0/0
tunnel mode gre multipoint
tunnel key 0
tunnel protection ipsec profile cisco
!
!GRE tunnel template for dynamically created GRE tunnels
!
interface GigabitEthernet0/0
description connected to cisco network, next hop:20.20.241.233
ip address 20.20.241.234 255.255.255.252
!
interface FastEthernet0/1/0
switchport access vlan 10
!
interface Vlan10
ip address 10.10.0.254 255.255.0.0
!
router eigrp 90
default-metric 100000 100 255 1 1500
network 3.3.3.0 0.0.0.255
network 10.10.0.0 0.0.255.255
network 192.168.10.0 0.0.0.255
!
ip route 0.0.0.0 0.0.0.0 20.20.241.233
!
Troubleshooting and Debugging
For detailed troubleshooting for the DMVPN, refer to the following guide:
http://www.cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a008014bcd7.shtml
These show commands check the status of the cryptography tunnels:
●
show crypto engine connection active: Displays the total encrypts and decrypts per security association
●
show crypto ipsec sa: Displays the statistics on the active tunnels
●
show crypto isakmp sa: Displays the state for the Internet Security Association and Key Management
Protocol (ISAKMP) security association