cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4214
Views
0
Helpful
4
Replies

DMVPN behind NAT

Smailmilak83_2
Level 1
Level 1

HI,

is there a way to configure a router as a spoke router where it does not have a PUBLIC IP?

It like this:

Spoke Router -> private IP -> NAT router -> Internet -> DMVPN Hub router

I tried it on 12.3(14)T7.

1 Accepted Solution

Accepted Solutions

Marcin Latosiewicz
Cisco Employee
Cisco Employee

There is no problem to have DMVPN spoke behind NAT.

Vide:

http://www.cisco.com/en/US/docs/ios/sec_secure_connectivity/configuration/guide/dmvpn_dt_spokes_b_nat_ps6441_TSD_Products_Configuration_Guide_Chapter.html#wp1060395

Usually on a stateful device you do not need to allow any ports for incoming traffic.

However UDP/500 and UDP/4500 will be needed if you use tunnel protection for DMVPN or GRE if you don't protect it with IPsec.

I'd suggest trying on a device with newer software. 12.4(15)Tx or 12.4(24)Tx ?

Marcin

View solution in original post

4 Replies 4

You will need to perform a one-to-one nat in your NAT router. Spoke Router Interface to a Public IP address.

You will have to permit ports GRE and UDP 500 and 4500 in the nat router since you will be working with NAT-T.

protocol GRE and ports UDP 500 and 4500.

Marcin Latosiewicz
Cisco Employee
Cisco Employee

There is no problem to have DMVPN spoke behind NAT.

Vide:

http://www.cisco.com/en/US/docs/ios/sec_secure_connectivity/configuration/guide/dmvpn_dt_spokes_b_nat_ps6441_TSD_Products_Configuration_Guide_Chapter.html#wp1060395

Usually on a stateful device you do not need to allow any ports for incoming traffic.

However UDP/500 and UDP/4500 will be needed if you use tunnel protection for DMVPN or GRE if you don't protect it with IPsec.

I'd suggest trying on a device with newer software. 12.4(15)Tx or 12.4(24)Tx ?

Marcin

I tried it on 12.4.25 and it worked behind NAT.

Thank you.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: