VPN's can really upset me.

Posted March 10th, 2009 by bcarroll and filed in CCIE Security, IPExpert Labs, Rants

I’ve come to the conclusion that if ANYTHING gets me in the lab on Friday its going to be VPN. With so many options and piling one solution on top of another (e.g. EasyVPN plus DMVPN on the same interface) I am totally screwed. I cruised thru lab 18 all morning. had about 41 points at lunch and since then have only managed to accumulate 6 points. NHRP isnt even registering. R2 is the NHS but gives me a lovely message when you bounce the tunnel interface that there are no NHSs:

R2#debug nhrp
NHRP protocol debugging is on
R2#conf t
Enter configuration commands, one per line. End with CNTL/Z.
R2(config)#int t256
R2(config-if)#shut
R2(config-if)#
*Mar 10 22:53:31.291: NHRP: if_down: Tunnel256 proto IPv4
*Mar 10 22:53:31.291: NHRP: if_down: Tunnel256 proto IPv4
R2(config-if)#
*Mar 10 22:53:31.295: %CRYPTO-6-ISAKMP_ON_OFF: ISAKMP is OFF
R2(config-if)#no s
*Mar 10 22:53:33.291: %LINK-5-CHANGED: Interface Tunnel256, changed state to administratively down
*Mar 10 22:53:34.291: %LINEPROTO-5-UPDOWN: Line protocol on Interface Tunnel256, changed state to down
R2(config-if)#no shut
R2(config-if)#
*Mar 10 22:53:36.331: NHRP: if_up: Tunnel256 proto 0
*Mar 10 22:53:37.331: NHRP: Unable to send Registration - no NHSes configured
R2(config-if)#
*Mar 10 22:53:38.331: %LINK-3-UPDOWN: Interface Tunnel256, changed state to up
*Mar 10 22:53:38.331: NHRP: if_up: Tunnel256 proto 0
*Mar 10 22:53:38.331: NHRP: Unable to send Registration - no NHSes configured
R2(config-if)#
*Mar 10 22:53:38.331: %CRYPTO-6-ISAKMP_ON_OFF: ISAKMP is ON
*Mar 10 22:53:39.331: NHRP: Unable to send Registration - no NHSes configured
*Mar 10 22:53:39.331: %LINEPROTO-5-UPDOWN: Line protocol on Interface Tunnel256, changed state to up
R2(config-if)#

I still have sections 9 – 12 but I am so frustrated right now that I have to go clear my head. Maybe I need to watch the DVDonDemand section on VPNs again. I thought I had them down pretty good. I must be missing something. Well enough of my ranting. Time to move on.

2 Responses to “VPN's can really upset me.”

  1. I’m sure you’ll do fine. You’ve been working hard on this track and regardless of the outcome on Fri, you’ll have gained that much more knowledge.

    And if you still have that nagging feeling that something is just not quite falling into place, I’d be happy to send some ‘divine supplication’ your way – I’m in pretty good standing with the Man upstairs ;-)

  2. Paul Stewart says:

    Brandon, I have confidence you are going to do well. There are a lot of options in the VPN arena and they are “touchy”. I just think you are going to hit a home run this go around. Let us know how it went as soon as you find out you passed!

Leave a Reply