<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Where should nat be configured if the DMVPN HUB is behind the ASA and the ASA is connected to internet using a service provider router in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/where-should-nat-be-configured-if-the-dmvpn-hub-is-behind-the/m-p/3706333#M414832</link>
    <description>I'd personally position the DMVPN Hub parallel with ASA, double natting on the ISP router and ASA overcomplicates the configuration and I don't know what issues could arise. &lt;BR /&gt;&lt;BR /&gt;I assume the ISP will configure a static NAT for you on their router? The DMVPN Hub needs a static NAT.&lt;BR /&gt;&lt;BR /&gt;It should be secure enough if you apply the ACL to the wan interface, permit only the traffic required (udp/500, udp/4500) esp is only needed if you do not NAT. Make sure you use the strongest algorthims e.g. IKEv2 with AES, SHA256, DH Group 19/21 and if using a PSK make sure it's of a decent length, else use certificates.&lt;BR /&gt;&lt;BR /&gt;HTH</description>
    <pubDate>Thu, 13 Sep 2018 14:21:58 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2018-09-13T14:21:58Z</dc:date>
    <item>
      <title>Where should nat be configured if the DMVPN HUB is behind the ASA and the ASA is connected to internet using a service provider router</title>
      <link>https://community.cisco.com/t5/network-security/where-should-nat-be-configured-if-the-dmvpn-hub-is-behind-the/m-p/3706053#M414825</link>
      <description>&lt;P&gt;Hi!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am struggling when configuring DMVPN hub behind ASA,where the ASA is connected to the ISP router to access internet.Any one has a solution for this matter.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:14:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/where-should-nat-be-configured-if-the-dmvpn-hub-is-behind-the/m-p/3706053#M414825</guid>
      <dc:creator>Viboosha paliyaguru</dc:creator>
      <dc:date>2020-02-21T16:14:12Z</dc:date>
    </item>
    <item>
      <title>Re: Where should nat be configured if the DMVPN HUB is behind the ASA and the ASA is connected to internet using a service provider router</title>
      <link>https://community.cisco.com/t5/network-security/where-should-nat-be-configured-if-the-dmvpn-hub-is-behind-the/m-p/3706096#M414826</link>
      <description>Hi,&lt;BR /&gt;You would need a static nat configured on the ASA for the HUB DMVPN router. You would need to modify the access-list on the ASA to permit udp/500 and udp/4500 to the HUB router.&lt;BR /&gt;&lt;BR /&gt;HTH</description>
      <pubDate>Thu, 13 Sep 2018 09:23:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/where-should-nat-be-configured-if-the-dmvpn-hub-is-behind-the/m-p/3706096#M414826</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-09-13T09:23:48Z</dc:date>
    </item>
    <item>
      <title>Re: Where should nat be configured if the DMVPN HUB is behind the ASA and the ASA is connected to internet using a service provider router</title>
      <link>https://community.cisco.com/t5/network-security/where-should-nat-be-configured-if-the-dmvpn-hub-is-behind-the/m-p/3706282#M414827</link>
      <description>&lt;P&gt;Hello.&lt;/P&gt;
&lt;P&gt;I managed to configure ASA static nat and allow UDP 4500 UDP 500.But the problem is how do i access the&amp;nbsp;DMVPN form internet through ISP router.Where the ISP router has a public IP not the ASA.&lt;/P&gt;
&lt;P&gt;Thank You!&lt;/P&gt;</description>
      <pubDate>Thu, 13 Sep 2018 13:35:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/where-should-nat-be-configured-if-the-dmvpn-hub-is-behind-the/m-p/3706282#M414827</guid>
      <dc:creator>Viboosha paliyaguru</dc:creator>
      <dc:date>2018-09-13T13:35:53Z</dc:date>
    </item>
    <item>
      <title>Re: Where should nat be configured if the DMVPN HUB is behind the ASA and the ASA is connected to internet using a service provider router</title>
      <link>https://community.cisco.com/t5/network-security/where-should-nat-be-configured-if-the-dmvpn-hub-is-behind-the/m-p/3706284#M414829</link>
      <description>Hello.&lt;BR /&gt;&lt;BR /&gt;I managed to configure ASA static nat and allow UDP 4500 UDP 500.But the problem is how do i access the DMVPN form internet through ISP router.Where the ISP router has a public IP not the ASA.&lt;BR /&gt;&lt;BR /&gt;Thank You</description>
      <pubDate>Thu, 13 Sep 2018 13:36:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/where-should-nat-be-configured-if-the-dmvpn-hub-is-behind-the/m-p/3706284#M414829</guid>
      <dc:creator>Viboosha paliyaguru</dc:creator>
      <dc:date>2018-09-13T13:36:45Z</dc:date>
    </item>
    <item>
      <title>Re: Where should nat be configured if the DMVPN HUB is behind the ASA and the ASA is connected to internet using a service provider router</title>
      <link>https://community.cisco.com/t5/network-security/where-should-nat-be-configured-if-the-dmvpn-hub-is-behind-the/m-p/3706287#M414830</link>
      <description>Ok, I understand I assumed you'd have a public IP address on the ASA. Obviously this a GNS3 lab, I assume you need to replicate in a live environment?&lt;BR /&gt;&lt;BR /&gt;Can you setup NAT on the ISP router? You could then put the DMVPN Hub router parallel with the ASA and not behind the ASA. You can lock down access to the DMVPN Hub router by applying an ACL to the wan interface.&lt;BR /&gt;&lt;BR /&gt;Otherwise you'd need a NAT from ISP router to ASA, then a NAT from ASA to DMVPN Hub.</description>
      <pubDate>Thu, 13 Sep 2018 13:44:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/where-should-nat-be-configured-if-the-dmvpn-hub-is-behind-the/m-p/3706287#M414830</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-09-13T13:44:31Z</dc:date>
    </item>
    <item>
      <title>Re: Where should nat be configured if the DMVPN HUB is behind the ASA and the ASA is connected to internet using a service provider router</title>
      <link>https://community.cisco.com/t5/network-security/where-should-nat-be-configured-if-the-dmvpn-hub-is-behind-the/m-p/3706326#M414831</link>
      <description>ISP router comes pre-configured from the ISP.&lt;BR /&gt;Will it downgrade the performance of the network if i NAT ISP TO ASA then NAT ASA TO DMVPN HUB?&lt;BR /&gt;Will it be secure without a firewall and use ACL to  lock down the  access to DMVPN HUB router  ?&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 13 Sep 2018 14:14:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/where-should-nat-be-configured-if-the-dmvpn-hub-is-behind-the/m-p/3706326#M414831</guid>
      <dc:creator>Viboosha paliyaguru</dc:creator>
      <dc:date>2018-09-13T14:14:40Z</dc:date>
    </item>
    <item>
      <title>Re: Where should nat be configured if the DMVPN HUB is behind the ASA and the ASA is connected to internet using a service provider router</title>
      <link>https://community.cisco.com/t5/network-security/where-should-nat-be-configured-if-the-dmvpn-hub-is-behind-the/m-p/3706333#M414832</link>
      <description>I'd personally position the DMVPN Hub parallel with ASA, double natting on the ISP router and ASA overcomplicates the configuration and I don't know what issues could arise. &lt;BR /&gt;&lt;BR /&gt;I assume the ISP will configure a static NAT for you on their router? The DMVPN Hub needs a static NAT.&lt;BR /&gt;&lt;BR /&gt;It should be secure enough if you apply the ACL to the wan interface, permit only the traffic required (udp/500, udp/4500) esp is only needed if you do not NAT. Make sure you use the strongest algorthims e.g. IKEv2 with AES, SHA256, DH Group 19/21 and if using a PSK make sure it's of a decent length, else use certificates.&lt;BR /&gt;&lt;BR /&gt;HTH</description>
      <pubDate>Thu, 13 Sep 2018 14:21:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/where-should-nat-be-configured-if-the-dmvpn-hub-is-behind-the/m-p/3706333#M414832</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-09-13T14:21:58Z</dc:date>
    </item>
  </channel>
</rss>

