<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Topic &#x27;DMVPN behind ASA (one to one NAT)&#x27; in forum &#x27;Cisco&#x27; - dslreports.com</title>
<link>http://www.dslreports.com/forum/DMVPN-behind-ASA-one-to-one-NAT-27647163</link>
<description></description>
<language>en</language>
<pubDate>Sat, 25 May 2013 04:10:47 EDT</pubDate>
<lastBuildDate>Sat, 25 May 2013 04:10:47 EDT</lastBuildDate>

<item>
<title>Re: DMVPN behind ASA (one to one NAT)</title>
<link>http://www.dslreports.com/forum/Re-DMVPN-behind-ASA-one-to-one-NAT-27648475</link>
<description><![CDATA[RyanG1 posted : post the relevant config (or all of it minus sensitive information) and also the errors you are seeing.<br><br>Ryan]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-DMVPN-behind-ASA-one-to-one-NAT-27648475</guid>
<pubDate>Mon, 22 Oct 2012 15:16:22 EDT</pubDate>
</item>

<item>
<title>DMVPN behind ASA (one to one NAT)</title>
<link>http://www.dslreports.com/forum/DMVPN-behind-ASA-one-to-one-NAT-27647163</link>
<description><![CDATA[krock83 posted : HI All,<br><br>I am having a fun little problem. One of the sites that recently opened up is getting their internet access from the Owners Network (this is a construction site at some University) so the site is getting the Internet access from the University. The issue here is that we need to get DMVPN working, but are unable to do so with this site because we are being NAT'ed through their ASA. <br><br>I have talked to the Security Engineer and he said the public IP that we are NAT'ed to is wide open to the internet (IP/TCP/UDP/GRE etc as well). Also I am able to ping the peer in our DC from our router behind the ASA, and have Internet access. What I dont have is the EIGRP neighbor relationship that is needed for internal LAN. When I do check the crypro isakamp sa I can see that the tunnel has been established with the peer. When I do sh crypto ipsec sa peer xx.yy.qq.ww I dont see any packets being encapsulated or decapsulated and I see a bunch of errors being sent out. <br><br><pre class="brush: text">Site859#sh crypto isakmp sa&#012;IPv4 Crypto ISAKMP SA&#012;dst             src             state          conn-id status&#012;20.53.62.58  10.10.10.2      QM_IDLE           2008 ACTIVE&#012; &#012;Site859#sh crypto ipsec sa peer 20.53.62.58&#012; &#012;interface: Tunnel900&#012;    Crypto map tag: Tunnel900-head-0, local addr 10.10.10.2&#012; &#012;   protected vrf: (none)&#012;   local  ident (addr/mask/prot/port): (10.10.10.2/255.255.255.255/47/0)&#012;   remote ident (addr/mask/prot/port): (20.53.62.58/255.255.255.255/47/0)&#012;   current_peer 20.53.62.58 port 500&#012;     PERMIT, flags={origin_is_acl,ipsec_sa_request_sent}&#012;    #pkts encaps: 0, #pkts encrypt: 0, #pkts digest: 0&#012;    #pkts decaps: 0, #pkts decrypt: 0, #pkts verify: 0&#012;    #pkts compressed: 0, #pkts decompressed: 0&#012;    #pkts not compressed: 0, #pkts compr. failed: 0&#012;    #pkts not decompressed: 0, #pkts decompress failed: 0&#012;    #send errors 121187, #recv errors 0&#012; &#012;     local crypto endpt.: 10.10.10.2, remote crypto endpt.: 20.53.62.58&#012;     path mtu 1500, ip mtu 1500, ip mtu idb FastEthernet4&#012;     current outbound spi: 0x0(0)&#012;     PFS (Y/N): N, DH group: none&#012; &#012;     inbound esp sas:&#012; &#012;     inbound ah sas:&#012; &#012;     inbound pcp sas:&#012; &#012;     outbound esp sas:&#012; &#012;     outbound ah sas:&#012; &#012;     outbound pcp sas:&#012; &#012;</pre><!--end code block--><br>Has any of you tried such confoigiration in the past? I have done some research online but I want able to follow some of the documentation out there. <br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/DMVPN-behind-ASA-one-to-one-NAT-27647163</guid>
<pubDate>Mon, 22 Oct 2012 10:12:31 EDT</pubDate>
</item>

</channel>
</rss>
