06-22-2010 11:51 PM - edited 02-21-2020 04:42 PM
does this scenario require as special configuration of the ASA? Up to now the setup is not working, we are facing the following problem:
The central DMVPN Hub shows a 'invalid SPI' error, because both spokes coming up with the same IP address (ASA hide-NAT) at the DMVPN hub.
thx
Holger
Solved! Go to Solution.
06-23-2010 08:26 AM
Are you using one IP address for both spokes? that is not gonna work
06-23-2010 08:25 AM
You will need to enable NAT-T in the all the routers and permit port udp 4500 as well from the outside of the ASA to the IP addresses of the spokes if it does't work permit all IP just to test. NAT will change the hash output so the spi will never be come up
06-23-2010 08:26 AM
Are you using one IP address for both spokes? that is not gonna work
06-24-2010 01:43 AM
Yes, of course, both DMVPN spokes are translated to one public PAT IP address.
And you are right, this configuration does not work.
see ASK THE EXPERT discussion
https://supportforums.cisco.com/message/3122613#3122613
thx for your reply
Holger
06-28-2012 12:28 AM
gadholwi1 написал(а):
see ASK THE EXPERT discussion
Hi! This link is not accessible
06-28-2012 01:14 AM
Can anybody confirm that two spokes won't work behind one PAT address on up to date software?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide