DMVPN ipsec tunnel no work ?
we are try do configure this http://vyos.net/wiki/DMVPN
but tunnel status is down and why create two tunnel ?
CLI Screen
vyos@spoke1:~$ show vpn ipsec sa
Peer ID / IP Local ID / IP
2.2.2.1 1.1.1.1
Tunnel State Bytes Out/In Encrypt Hash NAT-T A-Time L-Time Proto
tun0 down n/a n/a n/a no 0 3600 gre
Peer ID / IP Local ID / IP
0.0.0.0 1.1.1.1
Tunnel State Bytes Out/In Encrypt Hash NAT-T A-Time L-Time Proto
tun0 down n/a n/a n/a no 0 1800 gre
vyos@spoke1:~$ show vpn ipsec status
IPSec Process Running PID: 3294
0 Active IPsec Tunnels
IPsec Interfaces :
eth0 (no IP on interface statically configured as local-ip for any VPN peer)
maybe ipsec vpn something configure is wrong …
vyos 1.1.1.3
Feb 2 18:46:10 spoke1 pluto[3294]: “172.31.255.2-to-172.31.255.1” #3: ignoring informational payload, type INVALID_MESSAGE_ID
Feb 2 18:46:30 spoke1 pluto[3294]: “172.31.255.2-to-172.31.255.1” #3: ignoring informational payload, type INVALID_MESSAGE_ID
Feb 2 18:47:10 spoke1 pluto[3294]: “172.31.255.2-to-172.31.255.1” #5: max number of retransmissions (2) reached STATE_QUICK_I1. No acceptable response to our first Quick Mode message: perhaps peer likes no proposal
Feb 2 18:47:10 spoke1 pluto[3294]: “172.31.255.2-to-172.31.255.1” #5: starting keying attempt 3 of at most 3
Feb 2 18:47:10 spoke1 pluto[3294]: “172.31.255.2-to-172.31.255.1” #6: initiating Quick Mode PSK+ENCRYPT+UP to replace #5 {using isakmp#3}
Feb 2 18:47:10 spoke1 pluto[3294]: “172.31.255.2-to-172.31.255.1” #3: ignoring informational payload, type NO_PROPOSAL_CHOSEN
Feb 2 18:47:20 spoke1 pluto[3294]: “172.31.255.2-to-172.31.255.1” #3: ignoring informational payload, type INVALID_MESSAGE_ID
Feb 2 18:47:40 spoke1 pluto[3294]: “172.31.255.2-to-172.31.255.1” #3: ignoring informational payload, type INVALID_MESSAGE_ID
Feb 2 18:48:20 spoke1 pluto[3294]: “172.31.255.2-to-172.31.255.1” #6: max number of retransmissions (2) reached STATE_QUICK_I1. No acceptable response to our first Quick Mode message: perhaps peer likes no proposal