[c-nsp] GRE/MPLS

Peter Rathlev peter at rathlev.dk
Tue Jun 24 04:43:23 EDT 2008


On Tue, 2008-06-24 at 09:21 +0100, Timothy Arnold wrote:
> Hi,
> 
> I've got to terminate a remote site in to a customer's VRF using a GRE
>  tunnel. The tunnel comes up and I can ping across the tunnel and I can
>  also reach other hosts in the same VRF on the PE router that the
>  tunnel terminates. However I cannot reach any hosts on other PE
>  routers. For example, the traffic path is as follows
> 
> CE---GRE---PE-1---PE-2---FIREWALL
> 
> I don't see any ICMP packets hitting the firewall.

You're sure you're not seeing them reaching the firewall, right? So I
assume the problem isn't the return traffic.

> However, other hosts on PE1 are able to reach the firewall without any
>  issues. The GRE tunnel on PE-1 is in the correct VRF
<cut>
> It is strange how it only occurs with the GRE tunnel. Anyone have any
>  suggestions on how I can troubleshoot this further?

What platform/software is the CPE and the PEs? Can you do a trace from
the CPE and see at least PE1? Does the CPE use a static default towards
PE1?

Regards,
Peter




More information about the cisco-nsp mailing list