05-20-2008 05:53 AM - edited 02-21-2020 02:01 AM
Can somebody please send me a known working snippet of ASA config to support a DMVPN hub NAT'd behind an ASA. I tried for 2 days even with TAC and I was finally forced to put my DMVPN Hub out on the Internet with the IOS FW.
Basically the issue I was seeing was that ISAKMP would almost complete at the spoke, try to go to QM_IDLE and then start the ISAKMP process over. Tried different code revs, etc. The ASA is running 8.0.3. Works great as long as the ASA was not in the path.
Any help is appreciated.
06-15-2008 10:27 PM
Hey there I am trying to do the same type of setup with a 3845 behind an ASA5510/Sec plus and I am getting similar results.
I have access-lists permitting:
- ESP, ISAKMP, GRE, and 4500 to the router on the inside.
Have you made in head way to a solution?
06-16-2008 02:45 AM
Arthur,
I was not able to get it working and my attempts with TAC failed too. I ended up placing the DMVPN on the outside of the ASA and enabled the IOS FW features.
Please let me know if you find a solution.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide