12-23-2022 03:21 AM
I configured OSPF and BGP routes on my network (OSPF for the internal network and BGP for the external network) and distributed the BGP network on the OSPF route so the BGP route is advertised to the internal network. I have a NAT that translates my inside IP to the outside, but where do I advertise this NAT IP? Should I add on OSPF or BGP? I tried both but the outside network still can't reach the NAT IP. And I have DMVPN with IPsec protection, DMVPN is up but the host can't access the tunnel, or the hosts on both sides are connected by a route rather than a DMVPN tunnel. Can you help me, please?
12-23-2022 03:23 AM
can you draw the topology ?
12-23-2022 03:48 AM
Thanks for your reply, here is my topology
12-23-2022 03:54 AM - edited 12-23-2022 04:03 AM
the customer and Active-RTR and Standby-RTR are the run any routing protocol or static route additional to BGP ?
12-23-2022 05:29 AM
OSPF route is configured on Active-RTR only, no static route.
12-23-2022 05:33 AM
between active-rtr and customer I mean are you run any routing ?
12-23-2022 05:38 AM
The BGP route is configured on customer-rtr, active-rtr, and ISP-rtr, additionally, there is an OSPF route on the active-rtr.
12-23-2022 05:43 AM - edited 12-23-2022 05:52 AM
can you confirm that above is right ?
can you share the config I will run lab and see where is issue.
12-23-2022 06:05 AM
NAT IP is configured on the active router and when I configure a static route on the three routers(active, ISP, and Customer) the translation is working fine. But when I remove the static NAT and add the NAT IP on the BGP interface, it doesn't work or the NAT IP doesn't advertise from the active router to other routers. The nat IP does not have a direct interface on the active router, but when I configure the loopback interface for the NAT IP and use the "redistribute connected" command (on the three routers), it will be introduced on all routers. So my first question is where do I advertise the NAT IP on the active router? On an OSPF interface? On a BGP interface? Or do I need to configure a static NAT? Maybe if I fix this the traffic will reach the tunnel.
12-23-2022 06:10 AM
yes, you are right.
12-23-2022 06:37 AM
and active and standby rtr represent the Hub of dmvpn ?
12-23-2022 11:05 AM
in R1 and R2 I config Loopback
Lo 1.1.1.1/32 in R1
Lo 2.2.2.2/32 in R2
we advertise these LO in BGP to R3 (spoke)
now the issue of NAT
we need R3 not know any network except LO so we use NAT.
the issue is routing how we can solve this ? (below in both R1 and R2)
simply by PBR
we use route-map
route-map MHM permit 10
match ip add 100 <<- this acl can be permit ip any any
set interface loopback 0
then config PBR under R1 and R2 connect to R5.
and using
ip nat inside source list 1 interface loopback 0 overload
and success ping R6 and check the wiresharke I see Lo ip not 10.0.0.0 ip, so the config is OK.
12-23-2022 03:34 AM
Hello
can you confirm if the dmvpn nbma addressing is the pre-or post natted address?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide