Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

DMVPN Hub Behind ASA

Can somebody please send me a known working snippet of ASA config to support a DMVPN hub NAT'd behind an ASA. I tried for 2 days even with TAC and I was finally forced to put my DMVPN Hub out on the Internet with the IOS FW.

Basically the issue I was seeing was that ISAKMP would almost complete at the spoke, try to go to QM_IDLE and then start the ISAKMP process over. Tried different code revs, etc. The ASA is running 8.0.3. Works great as long as the ASA was not in the path.

Any help is appreciated.

New Member

Re: DMVPN Hub Behind ASA

Hey there I am trying to do the same type of setup with a 3845 behind an ASA5510/Sec plus and I am getting similar results.

I have access-lists permitting:

- ESP, ISAKMP, GRE, and 4500 to the router on the inside.

Have you made in head way to a solution?

New Member

Re: DMVPN Hub Behind ASA


I was not able to get it working and my attempts with TAC failed too. I ended up placing the DMVPN on the outside of the ASA and enabled the IOS FW features.

Please let me know if you find a solution.