cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
774
Views
0
Helpful
2
Replies

DMVPN Hub Behind ASA

patrickg
Level 1
Level 1

Can somebody please send me a known working snippet of ASA config to support a DMVPN hub NAT'd behind an ASA. I tried for 2 days even with TAC and I was finally forced to put my DMVPN Hub out on the Internet with the IOS FW.

Basically the issue I was seeing was that ISAKMP would almost complete at the spoke, try to go to QM_IDLE and then start the ISAKMP process over. Tried different code revs, etc. The ASA is running 8.0.3. Works great as long as the ASA was not in the path.

Any help is appreciated.

2 Replies 2

Arthur Kant
Level 1
Level 1

Hey there I am trying to do the same type of setup with a 3845 behind an ASA5510/Sec plus and I am getting similar results.

I have access-lists permitting:

- ESP, ISAKMP, GRE, and 4500 to the router on the inside.

Have you made in head way to a solution?

Arthur,

I was not able to get it working and my attempts with TAC failed too. I ended up placing the DMVPN on the outside of the ASA and enabled the IOS FW features.

Please let me know if you find a solution.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card