Cheers @Chipula,
We were using the same version on the 8500L as our ASR1001-X to keep some consistency while we changed platform as these are our DMVPN hubs.
As you said, Cisco TAC was trying to be helpful, but it was slow and they were requesting a joint troubleshooting session with Aruba.
Your thread gave us some more motivation try the latest recommended 17.12 so we got the green light to upgrade to that and it has so far resolved the issue with Aruba access points not properly establishing tunnels/SSIDs back to the controller.
While my initial google-fu didn't yield anything relevant other than your thread, I've since bumped into Cisco Bug CSCwe09298 which seemed to be the same, if not adjacent.
Thanks again for your feedback!
Original Message:
Sent: Jul 07, 2025 09:01 AM
From: Chipula
Subject: IPSec/GRE tunnel issues with AP's
I never got a clear answer from Cisco but we ended up using 17.6.X code and it was fine. We also tested 17.12.X but at that time it wasn't recommended for use but I believe it is now.
Original Message:
Sent: Jul 06, 2025 07:39 PM
From: dm0
Subject: IPSec/GRE tunnel issues with AP's
Apologies for resurrecting this @Chipula, but we've just migrated one of our Cisco ASR1001s to an Cisco 8500 that is in the traffic path between controllers and APs.
We kept as much the same as possible, including IOS version (17.9.5f), but we've hit this same issue. As we replaced our "secondary" first, we can troubleshoot live.
MTU was our first consideration but we've combed through the configuration, verified the working/not working routes are exactly the same with regards to MTU.
One cautious suspicion I have personally is that the router is incorrectly trying to process this specific IPsec traffic itself and dropping it (`show drops` has an abnormally high "IpsecIkeIndicate" compared to the operational one).
We're running this up the flagpole of Cisco support now but I'm keen to know - did you get to the bottom of this?