cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5093
Views
10
Helpful
3
Replies

urgent NAT-T DMVPN help?

can some one please provide me with the configuration of the DMVPN hub-server when the hub-server is configured with nat???

i`ll be thankfull.............

1 Accepted Solution

Accepted Solutions

Hi Mohammed,

I think you may want to check these links:

NAT-Transparency Aware DMVPN

"Also added in Cisco IOS Releases 12.3(9a) and 12.3(11)T is the capability to have the hub DMVPN router behind static NAT. This was a change in the ISAKMP NAT-T support. For this functionality to be used, all the DMVPN spoke routers and hub routers must be upgraded, and IPsec must use transport mode.

For these NAT-Transparency Aware enhancements to work, you must use IPsec transport mode on the transform set. Also, even though NAT-Transparency (IKE and IPsec) can support two peers (IKE and IPsec) being translated to the same IP address (using the UDP ports to differentiate them), this functionality is not supported for DMVPN. All DMVPN spokes must have a unique IP address after they have been NAT translated. They can have the same IP address before they are NAT translated."

Static NAT & DMVPN Hub ---> Another similar post.

Hope it helps.

Thanks.

Portu

Message was edited by: Javier Portuguez

View solution in original post

3 Replies 3

Hi Mohammed,

I think you may want to check these links:

NAT-Transparency Aware DMVPN

"Also added in Cisco IOS Releases 12.3(9a) and 12.3(11)T is the capability to have the hub DMVPN router behind static NAT. This was a change in the ISAKMP NAT-T support. For this functionality to be used, all the DMVPN spoke routers and hub routers must be upgraded, and IPsec must use transport mode.

For these NAT-Transparency Aware enhancements to work, you must use IPsec transport mode on the transform set. Also, even though NAT-Transparency (IKE and IPsec) can support two peers (IKE and IPsec) being translated to the same IP address (using the UDP ports to differentiate them), this functionality is not supported for DMVPN. All DMVPN spokes must have a unique IP address after they have been NAT translated. They can have the same IP address before they are NAT translated."

Static NAT & DMVPN Hub ---> Another similar post.

Hope it helps.

Thanks.

Portu

Message was edited by: Javier Portuguez

thanks a lot for your help

I am glad to hear that

Please mark this post as answered.

Portu.