Guest

Preview Tool

Cisco Bug: CSCvs29494 - Hub and spoke VPN, dynamic crypto map, auto-generated PSK is the same for static and dynamic peers

Last Modified

Dec 09, 2019

Products (1)

  • Cisco Firepower Management Center

Known Affected Releases

6.4.0.5 6.5.0

Description (partial)

Symptom:
After adding a dynamic IP spoke to hub and spoke topology, and automatically changing the crypto map type to dynamic, the pre-shared-key for all the spokes in topology is changed to the same value as for dynamic spokes.
A deployment to hub and all spokes is required, while unexpected, as there were no changes to the spokes.
Failing to deploy to all devices in topology creates an outage do to PSK changed on the hub.

Conditions:
Hub and spoke topology in FMC.
Auto generated pre-shared-keys used.
Adding a new spoke with dynamic IP to existing set of static IP spokes in topology, which forces crypto map type change to dynamic.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.