Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

two DMVPN Spokes behind ASA doing hide-NAT to the Internet

does this scenario require as special configuration of the ASA? Up to now the setup is not working, we are facing the following problem:

The central DMVPN Hub shows a 'invalid SPI' error, because both spokes coming up with the same IP address (ASA hide-NAT) at the DMVPN hub.

thx

Holger

1 ACCEPTED SOLUTION

Accepted Solutions

Re: two DMVPN Spokes behind ASA doing hide-NAT to the Internet

Are you using one IP address for both spokes?  that is not gonna work

5 REPLIES

Re: two DMVPN Spokes behind ASA doing hide-NAT to the Internet

You will need to enable NAT-T  in the all the routers and permit port udp 4500 as well  from the outside of the ASA to the IP addresses of the spokes if it does't work permit all IP just to test.   NAT will change the hash output so the spi will never be come up

Re: two DMVPN Spokes behind ASA doing hide-NAT to the Internet

Are you using one IP address for both spokes?  that is not gonna work

New Member

Re: two DMVPN Spokes behind ASA doing hide-NAT to the Internet

Yes, of course, both DMVPN spokes are translated to one public PAT IP address.

And you are right, this configuration does not work.

see ASK THE EXPERT discussion

https://supportforums.cisco.com/message/3122613#3122613

thx for your reply

Holger

two DMVPN Spokes behind ASA doing hide-NAT to the Internet

gadholwi1 написал(а):

see ASK THE EXPERT discussion

https://supportforums.cisco.com/message/3122613#3122613

Hi! This link is not accessible

two DMVPN Spokes behind ASA doing hide-NAT to the Internet

Can anybody confirm that two spokes won't work behind one PAT address on up to date software?

586
Views
0
Helpful
5
Replies