08-22-2022 08:50 AM
Hi DMVPN Pros
Maybe a DMVPN hero can help me out. I have a DMVPN setup with multiple spokes that are behind the same CGN (mobile 4G network). So there is a possibility that 2 CPEs may have the same public IP address after processing the CGN.
Is this a problem for the DMVPN Hub? Because I can read here: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_dmvpn/configuration/xe-17/sec-conn-dmvpn-xe-17-cat8000-book/sec-conn-dmvpn-dmvpn.html#GUID-284B12C0-9F18-42EE-9A77-29D368883C45
"For these NAT-Transparency Aware enhancements to work, you must use IPsec transport mode on the transform set. Also, even though NAT-Transparency (IKE and IPsec) can support two peers (IKE and IPsec) being translated to the same IP address (using the UDP ports to differentiate them), this functionality is not supported for DMVPN. All DMVPN spokes must have a unique IP address after they have been NAT translated. They can have the same IP address before they are NAT translated."
"If there is more than one DMVPN spoke behind the same NAT box, the NAT box must translate the DMVPN spokes to different outside NAT IP addresses."
If I have the same public IP address for more than one DMVPN Spoke, is it then a general problem that the connection between this spokes and the hub is broken? Or are just some features or some special scenarios broken?
Solved! Go to Solution.
08-23-2022 01:49 PM
https://www.trueneutral.eu/2017/dmvpn-mobile-blues.html
check this solution.
if you have any Q you free to ask any thing
08-22-2022 09:01 AM
Hello,
there is no way you can have identical public IP addresses. Carrier Grade NAT is implemented by the ISP. Where did you get the information that there is a chance for duplicate public IP addresses ?
08-22-2022 09:03 AM - edited 08-22-2022 09:05 AM
The more routers I have, the greater the probability that two will get translated to the same Public IP from the ISP, when he is doing CGN.
08-22-2022 09:22 AM
Hello,
can you post the source of that ? Did your ISP tell you that ?
06-04-2023 06:00 PM
from experience
10-15-2023 06:21 PM
i fixed this issue by using two different apns
06-04-2023 06:00 PM
What do you make of this? Two spokes sharing same IP behind CGN
08-22-2022 09:06 AM
https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_dmvpn/configuration/xe-16-9/sec-conn-dmvpn-xe-16-9-book/sec-conn-dmvpn-dt-spokes-b-nat.pdf
check this doc. for the DMVPN with NAT
08-23-2022 08:01 AM - last edited on 08-24-2022 11:22 PM by Translator
Thank you for the document. The document describes the
Spoke-to-Spoke
Tunnels. What I like to know is, if the
Spoke-to-Hub
tunnels will also have problems, if two Spokes are translated to the same public IP address.
08-23-2022 08:33 AM
I will make review send solution.
08-23-2022 01:49 PM
https://www.trueneutral.eu/2017/dmvpn-mobile-blues.html
check this solution.
if you have any Q you free to ask any thing
04-13-2024 08:28 PM
If two or more spokes get the same IP, only one tunnel will kept and others dropped. Reboot the devices so they get different IP for all spokes to be connected.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide