I have a DMVPN scenario, and it works very fine. Now I would like to put a new Hub router, as backup, and between HUB1 and HUB2, I have configured HSRP and the spokes routers connect in the Virtual IP Address.
After this configuration, the vpn goes down.
So I need help to solve this issue in this scenario, DMVPN with primary and secondary HUB.
When using pure IPsec with two hubs where you need redundancy, you have to combine this with a mechanism like HSRP. This is because we cannot run a dynamic routing protocol through the pure IPsec tunnels to help out with forwarding traffic. So the Stateful IPsec feature was added to specifically have IPsec work with HSRP and keep the IPsec and ISAKMP SA databases synchronized between the two HSRP routers. Therefore HSRP can switch the encrypted traffic between the two HSRP routers as necessary without too much loss of traffic. REfer URL
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
Table of Contents Introduction:This document describes details on how
NAT-T works. Background: ESP encrypts all critical information,
encapsulating the entire inner TCP/UDP datagram within an ESP header.
ESP is an IP protocol in the same sense that TCP an...