I don't think this will be a problem since DMVPN supports spokes behind NAT devices, but I'm planning on changing my network around for security and redudancy reasons and putting a pair of ASA firewalls on my collocation Internet connection. Right now I have a 3845 running DMVPN , NAT & ZBFW. I'm going to remove the ZBFW and move NAT to the ASA, leaving only the DMVPN hub and routing. If I create a static NAT mapping on my ASA to point to the DMVPN hub will this work?
I think it will, but I just wanted to be 110% sure.
DMVPN with static NAT on hub is supported setup. Just be awear there are some limitations.
1, all DMVPN router, hub and spokes have to run at least 12.3(9a) and 12.3(11)T code.
2, must use ipsec transport mode.
3, If need dynamic spoke to spoke tunnel, hub has to run at least 12.3(13), 12.3(14)T or 12.3(11)T3 code.
Check the configuration guide