cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1279
Views
8
Helpful
5
Replies

IWAN Branch Router reachability to controller

vishal-patil
Level 1
Level 1

Hello,

I am new to the concept of IWAN and trying to deploy branch site through apic-em IWAN app (rough topo diagram attached). The hub site is deployed successfully with iwan app

The branch router is booting with bootstrap (in bootstrap, NATed IP is used which is 20.20.20.3)

For some reason branch router cannot contact apic-em

Also, configured below nat configuration on hub2 router -

ip nat inside source static 10.10.10.1 20.20.20.3 vrf IWAN-TRANSPORT-2

Any suggestion?


Thanks,

Vish

1 Accepted Solution

Accepted Solutions

The NAT is not vrf aware and so I had to configure VASI on the inet hub router in order to reach the controller IP.

Its working now. Thanks

View solution in original post

5 Replies 5

cchitnis
Cisco Employee
Cisco Employee

"Spoke (branch) behind NAT" use-case is not supported till now. It will be supported from upcoming release (1.4)

But I am trying to nat apic em IP on Hub border router

Can you share your bootstrap config? Specifically, the route to reach to controller (must be default route I'm assuming)

Additionally, if hub is in configured state, can you share the existing config (of the hub where NAT is configured). Specifically, the networks routed through this hub and ACLs in place?

I'm assuming you are bringing up the device through PNP. If so, in your PNP profile, if you are trying to reach PNP server on APIC-EM, is it reachable from device?

If your Hubs are provisioned can you please check and let us know if the subnet in which controller resides is being advertised all the way through to the branch - via routing or other static routes? Clearly, it's routing that's lacking in your set-up that's causing no connection between your branch and the controller.

The NAT is not vrf aware and so I had to configure VASI on the inet hub router in order to reach the controller IP.

Its working now. Thanks