Cisco Bug: CSCvs29494 - Hub and spoke VPN, dynamic crypto map, auto-generated PSK is the same for static and dynamic peers
Jul 29, 2020
- Cisco Firepower Management Center
Known Affected Releases
Symptom: After adding a dynamic IP spoke to hub and spoke topology, and automatically changing the crypto map type to dynamic, the pre-shared-key for all the spokes in topology is changed to the same value as for dynamic spokes. A deployment to hub and all spokes is required, while unexpected, as there were no changes to the spokes. Failing to deploy to all devices in topology creates an outage do to PSK changed on the hub. Conditions: Hub and spoke topology in FMC. Auto generated pre-shared-keys used. Adding a new spoke with dynamic IP to existing set of static IP spokes in topology, which forces crypto map type change to dynamic.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.
Bug Details Include
- Full Description (including symptoms, conditions and workarounds)
- Known Fixed Releases
- Related Community Discussions
- Number of Related Support Cases