06-28-2018 08:25 PM - edited 03-05-2019 10:41 AM
Dear Team,
I have configured DMVPN between HUB and Spook with spook having Dynamic ip (Nat behind local ADSL Router with dynamic ip). I have used OSPF as routing protocol. My DMVPN is also up, route is advertised in OSPF. I am able to ping lan IP configured in HUB Router (Cisco 2911). All traffic from spook is send to HUB. I have send my default route from HUB to My upstream Firewall (fortigate or Sophos) to access my core services as well for Internet.
Now my main Problem is,
However despite all thing branch is not able to access any services or access internet hosted in or behind HUB firewall.
Your assistance to resolve this issue will be appreciated.
Thanks in advance
06-28-2018 08:43 PM
Hi
As soon as you have your Nat and dmvpn is fully up (nhrp, crypto and dynamic routing is up) you shouldn't have any issue. The difference between fix wan and dynamic wan ip is just for building up the tunnel but after there's nothing different.
Do you have all route advertised and received for this spoke on the spoke side and hub side?
Can you share some outputs like:
- sh dmvpn
- sh ip ospf neig
- sh ip route
- traceroute
Please give outputs for spoke and hub and attach them to a text file you'll upload on this post