DMVPN router behind ASA - need help please.

Hello

After reading many other discussions on this topic, it appears with the correct IOS and NAT - T active router, you bring up DMVPN behind a NAT device.

I tried to perform this task, but I can not even phase 1 going to the DMVPN. The routing was checked and I can ping the routers DMVPN public IP. I'm sure that the configurations for routers are good, but asked if any additional NAT is required on the ASA.

Here is the topology:

Plate rotating DMVPN > ASA > Internet > ASA > DMVPN Branch

The SAA on the side of the hub is in our data center and in production with several site-to-site and traffic to DMZ. Devices DMVPN is a Cisco 2921 and 1921. When I run a "debug crypto isakmp" on both routers, I see ISAKMP messages are sent on the branch DMVPN router. Nothing in the hub and no hits on the ASA ACL. I tried both the public IP address and the private IP address of the ACL on the ASA.

I have attached the relevant training and can post more if necessary.

Thank you

Brandon

Hello

I finally had time to laboratory it.

I used this topology:

I have

ASA (config) # sh run nat
NAT (INSIDE, OUTSIDE) static source HUB-ROUTER-REAL-IP interface service udp-eq-4500 udp-eq-4500
NAT (INSIDE, OUTSIDE) static source HUB-ROUTER-REAL-IP interface service udp-eq-500 udp-eq-500
!
object network HUB
dynamic NAT interface (INSIDE, OUTSIDE)

ASA (config) # sh run access-list
extended OUTSIDE permitted udp access list any HUB-ROUTER-REAL-IP eq isakmp object
list access extended OUTSIDE permitted udp any eq HUB-ROUTER-REAL-IP 4500

R2 #sh run inter t0

interface Tunnel0
172.16.0.1 IP address 255.255.255.0
no ip redirection
no ip next-hop-self eigrp 1
no ip split horizon eigrp 1
dynamic multicast of IP PNDH map
PNDH id network IP-99
source of tunnel FastEthernet0/0
multipoint gre tunnel mode
tunnel key 100000
Tunnel ipsec DMVPN-IPSEC-PROFILE protection profile

So it should be the same configuration that you use.

The only thing is that I had to ' stop/no shut' tunnel interface and removing some config that I also need to clear the connection on the ASA using "clear conn."

R2 #sh dmvpn
Legend: Attrb--> S - static, D - dynamic, I - incomplete
Local N - using a NAT, L-, X - no Socket
# Ent--> entries number of the PNDH with same counterpart NBMA
State of the NHS: E--> RSVPs, R--> answer, W--> waiting
UpDn time--> upward or down time for a Tunnel
==========================================================================

Interface: Tunnel0, IPv4 PNDH details
Type: hub, PNDH peers: 2,.

# Ent Peer NBMA Peer Tunnel Addr add State UpDn Tm Attrb
----- --------------- --------------- ----- -------- -----
1 200.20.0.10 172.16.0.2 UNTIL 00:11:28
1 200.30.0.10 172.16.0.3 AT 00:11:22

R2 #.

Tags: Cisco Security

Similar Questions

Maybe you are looking for

  • Photo transfer iPhotos library

    iPhotos crash on my iMac, so I think it would be better now to transfer everything to the Photos App. How can I do this and how would retain the albums that I put in place? I use iPhoto for all my digital scrapbooking kits and they are set up as even

  • Java no longer works on Firefox.

    I got the update of Java 6 31. Chrome, I had, and it worked fine. Subsequently, there was an update of Java 7 9 update. Due to an error, I couldn't install Java 7, so I stuck with the update of Java 6 31. However, it did not work. I activated the ext

  • All-in-one: how to analyze when the printer is broken?

    Hello. I have a HP 4480 all-in-one, and the printer stopped working earlier. I think it's really broken, the print heads seem to be stuck. Well, I don't really mind, I have an older printer that does work, but the scanner no longer works, asking the

  • Need diagram to check the close switch cover for dell inspiron 1525

    Need schematics for Dell Inspiron 1525, check the following points: proximity LCD cover switch cable from the motherboard to the inverter How to check the inverter Thank you

  • Photosmart C4180 all-in-One.

    last week the printer does nothing more. the bottom of power blinks all the time and it is not possible to turn on or off. I unplugged the power cable already and uninstalled the software and installed again, but problem not solved. I get the message