Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Community Member

Trouble Completing IPsec Proposal - NAT Issue ???

I have a functioning DMVPN environment running with two hubs and approx 95 remote offices using 2621XM VPN Bundles. They have been functioning well for quite a few years now. I am now trying to bring up a new office with a couple of differences, this time I'm using a 2821VPN Bundle and will be configuring the tunnel through a NAT router (one side Internet, the other private). I am able to bring up ISAKMP portion of the tunnel with no issues, however when I get to the IPSec (transport mode) proposal the IPSec tunnel never completes and fails on the hub side with the following error message:

003565: May 8 14:07:38.731 edt: map_db_find_best did not find matching map

003566: May 8 14:07:38.731 edt: IPSEC(validate_transform_proposal): no IPSEC cryptomap exists for local address a.a.a.a.

Router configs of one of the Hubs (the other is identical) the NAT router and the Spoke router are included as well as the IPSec debug from the hub and spoke. See attachment for more detail.

Thanks

Mike

1 REPLY
Community Member

Re: Trouble Completing IPsec Proposal - NAT Issue ???

Issue resolved, not by coming up with a solution to the NAT problem, rather I was able to have the carrier provide us an Internet routeable 29 bit network on the inside of their router.

Mike

223
Views
0
Helpful
1
Replies
CreatePlease to create content