DMVPN+IPSec+CA Server Implementation


I am having some trouble to implement DMVPN+IPSec+CA Server. I am receiving the following error message: Nov 20 20:45:21.126: %CRYPTO-4-RECVD_PKT_NOT_IPSEC: Rec'd packet not an IPSEC packet. (ip) vrf/dest_addr= /, src_addr=, prot= 47.

Attached the configuration applied.

I've set up this lab because I need to replace a DMVPN Hub+CA Server Router in an operational environment, due to the Cisco Clock Signal Component Issue (

Any help would be useful.



  • I wasn't able to view the config file but it sounds like you don't have the "tunnel protect ipsec profile PROFILE" added to the tunnel interface. Can you show us that part of the config and the relevant portion of "show run | sec crypto" please.

Sign In or Register to comment.