Forum Discussion

KernelPanic's avatar
KernelPanic
Icon for Nimbostratus rankNimbostratus
Sep 19, 2013

IPSEC Affinity Not Working

I have an HA LTM in load balancing Cisco DMVPN connections to four hub routers 10.20.1.101, 2, 3, & 4. Problem is that it's load balancing the ISAKMP and ESP to different hub routers, as you can see from the connection table. What's the simplest way to get the ISAKMP/ESP from the public source address (left) to the same hub router (right)? I have a simple configuration with a vip, one pool with four members and no snat, let me know if you need to see more. THANKS!! [root@etc-rslb-dmvpn-1:Active:Changes Pending] config tmsh show sys connection | grep 172.16.1.10: 99.126.100.55:500 172.16.1.10:500 99.126.100.55:61936 10.20.1.104:500 udp 5 (tmm: 1) 99.108.26.170:500 172.16.1.10:500 99.108.26.170:500 10.20.1.101:500 udp 5 (tmm: 3) 99.126.100.55:4500 172.16.1.10:4500 99.126.100.55:35306 10.20.1.103:4500 udp 4 (tmm: 1) 99.108.26.170:4500 172.16.1.10:4500 99.108.26.170:50000 10.20.1.103:4500 udp 4 (tmm: 3) 108.86.114.132:4500 172.16.1.10:4500 108.86.114.132:23287 10.20.1.104:4500 udp 0 (tmm: 3)

 

11 Replies