DMVPN Hub IP address change

Hi all!

I'm upgrading to our network environment in the coming months to include a redundant Internet connection.  This change is requireing our ISP go us from a 30 to a 29.  Currently the 3845 router I have in the 30 subnet is the DMVPN hub for our 8 remote teleworkers with 881 routers in their home offices.

The preparation of this change of IP address, my thoughts were to create a new interface of GRE tunnel with the new parameters of DMVPN hub before the address change IP takes place. Once we move to the 29, the spoke routers should be able to reconnect to our network under the new tunnel interface.  We run EIGRP on our DMVPN, so all roads should change to the new interface to tunnel those tunnels is in place.

Is this the best way to handle this?

Thanks for all your comments!


I don't think that there is a better way to cope than what you plan to do.

Create a new one with the new IP address, once it is able to reach is it will come automatically upward and forward it on this tunnel.

Or ask your ISP to allow you to keep the old 30 space for a week to do a graceful migration

Tags: Cisco Security

Similar Questions

  • DMVPN hub & spokes multiple w / same subnet

    I have several (about 70) sites, but each site has the exact same LAN ( each site has an ISR800.

    To my home office, I have a configured (ISR4331) DMVPN hub.  To my home office, I have a network that each of the customers on my shelves need to access (

    Any other access to the customers talk should go directly to the internet through this connection wan routers.  Rays will never talk to each other.

    My tunnels are all in the, with \ being the hub network.

    What is the best way to do it?  I feel like some sort of NAT would be the solution, but do not know what direction to look in.  I found that other positions on duplicate networks, but only for duplication of unique network... not 70 x.

    I think I'd be considered for use instead of DMVPN EasyVPN server.  He can do NAT for you automatically.

    Otherwise if you use DMVPN, then Yes, you will need to NAT each LAN to address IP Tunnel.  Just treat the external interface of Tunnel like any other IP address.  You will need to use a road map to match the traffic destined for the Internet interface and another for traffic going to the Tunnel interface.

    Something like:

    ip nat inside source route-map NAT-TUNNEL interface Tunnel0 overloadip nat inside source route-map NAT-INTERNET interface Dialer0 overload
    access-list 105 permit ip any
    route-map NAT-TUNNEL permit 10 match ip address 105 match interface Tunnel0!route-map NAT-INTERNET permit 10 match ip address 105 match interface Dialer0
  • Static NAT & DMVPN Hub


    I don't think that will be a problem DMVPN supports the rays behind NAT devices, but I anticipate change my network for reasons of security and redudancy autour and putting a pair of ASA firewalls on my Internet collocation.  Right now I have a DMVPN race 3845, NAT & ZBFW.  I'm going to remove the ZBFW and move the NAT to the ASA, leaving only the DMVPN hub and routing.  If I create a static NAT mapping on my ASA to point to the DMVPN hub that will work?

    I think it will be, but I just wanted to be 110% sure.

    Thank you!

    Hi Brantley,

    DMVPN with static NAT on the hub is supported in the installer. Just be awear it there are limits.

    1, all DMVPN router, hub and spokes must be running at least 12.3(9a) and 12.3 (11) T code.

    2, must use ipsec transport mode.

    3, so need dynamic tunnel talk to rays, hub should work at least 12.3 (13), 12.3 (14) T and 12.3 (11) T3 code.

    See the configuration guide


    Lei Tian

  • DMVPN - Hub Hub behind PIX, rays on the outside

    Hi all

    Someone at - it examples of configuration with DMVPN, where the hub is behind a PIX and the rays are on the outside. Inside of ownership intellectual of the hub must be NAT' static ed to the hub inside.


    «Also added in Cisco IOS release 12.3(9a) and 12.3 (11) T is the ability to make router DMVPN hub behind static NAT.» It was a change in the support of ISAKMP NAT - T. For this feature to use DMVPN spoke all routers and routers hub must be upgraded and IPSec must use the mode of transport. "

    I would like to know if this link helps

  • Satellite L750D - MAC address change by itself

    Satellite L750D/L755D 18mths old.
    Restarted this morning after the weekend and cable NIC MAC address has chnaged.

    Started in windows and could see a different value to Friday (as we control access through MAC address and was blocked).
    Started in normal Linux (Ubuntu 12.04) and a different MAC address again.

    NIC seems to work fine with whatever he chooses - but how MAC address can be change by itself?

    > NIC seems to work fine with whatever he chooses - but how MAC address can be change by itself?

    The physical MAC address is not editable, but there are a few ways to spoof the mac address
    For example, using Windows XP, the MAC address can be changed in the properties of the Ethernet adapter. On the Advanced tab, under "MAC address", "Locally administered address", "Ethernet address" or "network address". The name of this option depends on the Lan driver that is installed on your laptop. And important note; not all drivers are supported changing the MAC address of this way.

    In addition the system registry key:
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\Class\ {4D36E972-E325-11CE-BFC1-08002BE10318} contains some parameters of the network interface and the option called NetworkAddress will serve to set the MAC address.

    There are also tools that could spoof the address MAC for example, SMAC MAC Address Changer.
    Finally and above all some routers provide an option to change the MAC address.

  • PSC IP address changes when disconnected


    I have a 2200 CFP with 1 input module of the I-110, 1 output of AO-200 and 1 relay RLY-423 module module. Whenever I have to unplug the power supply from the system of the CFP, then again plug the IP address changes. I wonder what I have to do to keep the same IP address when I unplug the system? Thanks for the help


    There is a dip on the controller marked PSC IP RESET switch.  Make sure that it is in "OFF" position.

    Make sure that you configure the CFP to use a "static" IP address

  • PAP2T loses the connection when the external ip address changes

    I have a PAP2T adapter connected behind a Netgear DG834GT router.  Usually, I have no problem, however, my ISP has been known to change the dynamic IP address from time to time.  In this case the adapter will stay online until the reg expires during which he is not able to save the time and I get the error "unable to connect to the server.  Therefore, the only way I can get the adapter to work again is to restart the router, then restart the adapter.  If I reboot the adapter only it will not connect.

    I have the router providing a fixed ip address via DHCP. I have active STUN and the I the active NAT and NAT keepalive mapping.  The "reg expires" is set to 60.  When the adapter is connected correctly, it shows the external IP correctly.  However, it will not update after the external ip address change until I have restart the router and adapter.  I thought to get a static IP address, but try to avoid paying for it. Is this a common problem?

    I'm rather new to VOIP and I hope I have given you enough information.  Any help would be appreciated.

    Thank you


    I finally got to work.  It turns out that I had to do an update of the firmware on the router and then place the card in the demilitarized zone.

  • Hardware requirements for DMVPN HUB

    Hi all

    is that anyone can confirm that the 1841 below can take over as dmvpn HUB for 3 spoke?

    Cisco 1841 (revision 6.0) with 222208 K/K 39936 bytes of memory.
    Card processor ID FCZ10xxxxxxx
    2 FastEthernet interfaces
    1 module of virtual private network (VPN)
    Configuration of DRAM is 64 bits wide with disabled parity.
    191K bytes of NVRAM memory.
    126000K bytes of ATA CompactFlash (read/write)

    Thanks in advance,


    OK, 1 MBit is easy for a 1841.

    15.0 (1) M10 is the actual release under 15.0 and 15.1 (4) M10 is the Cisco proposed release. I would upgrade the router before going live if possible. If you have no support contract, running IOS should also be fine.

  • If the case change the ip address change active directory Microsoft that this issue face our windows network.

    If the case change the ip address change active directory Microsoft that this issue face our windows network.

    as matter
    1. any client machine ip address change.

    Hi Andrew,

    The question you posted would be better suited to the TechNet community. Please visit the link below to find a community that will provide the support you want.

    Hope this information is useful.

  • Is it possible to put behind a NAT DMVPN hub? (Speaks has a public IP address)

    I he tried for a few days and couldn't make it work. The schema and configuration is in the attachment.

    Crypto isakmp profile: QM slowed down on both sides.

    Profile of crypto ipsec: NO ipsec profile established on both sides.

    Show ip PNDH (side hub): nothing is saved at all. Empty.

    Any ideas?

    Thank you!


    As long as the HUB has a static nat translation it should work, try to set your transformation mode of Transport rather than tunnel on two spokes and hub, close your tunnel on the hub and the spokes and then turn it back on, does make a difference?

  • I can't see a message from my Union because of problems with the address changed for pop-upwindows and some other issues

    I am from Sweden and I have problems with a Web site that has my Union. I could see messages from them before, but they changed their address and on the site, they say people that they must put the new address on the approved list of the pop-up windows. I did but it still does not. Maybe I did wrong, I don't know, but it's annoying as hell that I can't see the messages they send.

    I really need help with that.

    Best regards

    You can control and manage permissions for all areas on the Subject: authorizations page.

    You can delete all data stored in Firefox with a specific area through "Forget this Site" from the context menu of the history entry (see the history or the history sidebar) or via the subject: permissions page.

    Using "Forget this Site" will delete all data stored in Firefox in this area as bookmarks, cookies, words of past, cache, history, and exceptions, so be careful and if you have a password or other data from this area you don't want to lose so take note of these passwords and bookmarks.
    You can't recover from which "forget" unless you have a backup of the affected files.

    It has no lasting effect, so if come back you on such a 'forgotten' site, then the data of this Web site will be saved once more.

  • Address bar does not match tab is selected. How can I get the address change and correspond to the tab I select a tab that has been previously loaded?

    If I open a new tab and type a url in the address bar tab load very well. When I return to an already open tab, the tab looks fine, but the address bar still shows that last typed url, not the url of the 'active' tab I do not see the url of the active tab and I can't use the "return", "Refresh", etc...

    Start Firefox in Firefox to solve the issues in Safe Mode to check if one of the extensions of the origin of the problem (switch to the DEFAULT theme: Firefox (Tools) > Add-ons > appearance/themes).

  • Blocked or delete Wifi Mac address & change to the original iPhone address Wifi 6 more

    Please change address of Mac Wifi on my iPhone camera Plus 6 and secure it will solve.

    someone hack my connection to internet initial IP address.

    I want to know what the actual address iPhone wifi 6 Plus.

    Thank you.

    The address real wifi to your phone depends on the address given by your router, unless you tell us what it is that we cannot know the answer to the question.

  • CRio inside the schools network, IP addresses change and causing problems


    We have about five CRio modules in our labs, and they are connected by ethernet to our school system. We use all these CRios for about 3-5 different computers.

    We have a problem which, because of internet IP addresses security are changed for a certain period of time, i.e. every two months. We must always know from the measurement and Automation Explorer which is the IP and then change on demand (.VI) and then compile new .exe file, and then copy it to other computers.

    Is there an easy way to keep the CRio IP to the same (can 'lock us'?) or is there an easy way to do it within the .VI, without doing each time again and again for all computers.

    In your LabVIEW project, you can right-click on the controller, select Properties, and then change the IP address for the host name. If you use IP addresses in your screws, you should be able to simply replace the IP address with the host name in most cases.

    Jason S.

  • HP envy 4500: IP address changed

    By default my printer comes past in offline mode and the only way I can get it's back online to re - install everything (this is the 7th time).  Recently, I noticed that the IP address has changed and I never changed it.  Is there a way to change the wireless connection without having to reinstall everything.  Anyone happen to know why the IP address also changes.

    Hi shorty_tg

    Normally when we reboot the wifi, the IP address may vary. And again, this is not consistent.

    Having a static IP address on your machine should solve your problem.

    The IP address is normally displayed when you click on the wireless / wired network icon located on the top line of the touch screen to your printer.

    Kind regards


Maybe you are looking for