Guest

Preview Tool

Cisco Bug: CSCuq38657 - Multiple blank lines shows up in 'show dmvpn detail' output

Last Modified

Sep 14, 2019

Products (25)

  • Cisco IOS
  • Cisco ASR 901-6CZ-F-D Router
  • Cisco 7301 Router
  • Cisco 7206 Router
  • Cisco ASR 901-4C-FT-D Router
  • Cisco ME 3600X-24TS-M Switch
  • Cisco 7204 Router
  • Cisco ASR 901-6CZ-F-A Router
  • Cisco 7206VXR Router
  • Cisco ASR 901-6CZ-FT-A Router
View all products in Bug Search Tool Login Required

Known Affected Releases

15.2(4)S 15.2(4)S1 15.3(3)S2

Description (partial)

Symptom:
Multiple blank lines are seen in the 'show dmvpn detail' output right after the 'Pending DMVPN Sessions' section when there are multiple crypto sessions in 'Down-Negotiating' state. 

So, normally, when all the crypto sessions are in 'UP-ACTIVE' state, we only see a single blank line below the 'Pending DMVPN Sessions' section in the 'show dmvpn detail' output however when there is a single 'Down-Negotiating' crypto session, we're seeing two blank lines and the number of blank lines increases to a large number when there are a lot of crypto sessions in 'Down-Negotiating' state in a DMVPN setup.

Conditions:
When the crypto session for a DMVPN tunnel goes in 'Down-Negotiating' state, the output of 'show dmvpn detail' shows a blank line right after 'Pending DMVPN Sessions' section per 'Down-Negotiating' session. So, if there is one crypto session in 'Down Negotiating' state, we'll see two blank lines below the 'Pending DMVPN Sessions' section.


Hub-R1#show dmv detail
Legend: Attrb --> S - Static, D - Dynamic, I - Incomplete
        N - NATed, L - Local, X - No Socket
        # Ent --> Number of NHRP entries with same NBMA peer
        NHS Status: E --> Expecting Replies, R --> Responding, W --> Waiting
        UpDn Time --> Up or Down Time for a Tunnel
==========================================================================

Interface Tunnel0 is up/up, Addr. is 172.16.1.1, VRF ""
   Tunnel Src./Dest. addr: 1.1.1.2/MGRE, Tunnel VRF ""
   Protocol/Transport: "multi-GRE/IP", Protect "DMVPN"
   Interface State Control: Disabled
   nhrp event-publisher : Disabled
Type:Hub, Total NBMA Peers (v4/v6): 1

# Ent  Peer NBMA Addr Peer Tunnel Add State  UpDn Tm Attrb    Target Network
----- --------------- --------------- ----- -------- ----- -----------------
    1 2.2.2.2              172.16.1.2    UP 00:22:20    D      172.16.1.2/32


Crypto Session Details:
--------------------------------------------------------------------------------

Interface: Tunnel0
Session: [0xF0198EC0]
  IKEv1 SA: local 1.1.1.2/500 remote 2.2.2.2/500 Active
          Capabilities:(none) connid:1001 lifetime:23:37:39
  Crypto Session Status: UP-ACTIVE
  fvrf: (none), Phase1_id: 2.2.2.2
  IPSEC FLOW: permit 47 host 1.1.1.2 host 2.2.2.2
        Active SAs: 2, origin: crypto map
        Inbound:  #pkts dec'ed 308 drop 0 life (KB/Sec) 4197513/2259
        Outbound: #pkts enc'ed 310 drop 0 life (KB/Sec) 4197513/2259
   Outbound SPI : 0x540DB8E8, transform : esp-aes esp-sha-hmac
    Socket State: Open

Pending DMVPN Sessions:
                                              >>>>>One blank line (which already existed)
                			      >>>>>Another blank line appears when one of the tunnels is down & is in 'Down-Negotiating' state
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.