troubleshooting Question

can dmvpn and ipsec coexist together

Avatar of nabeel92
nabeel92 asked on
RoutersVPNSwitches / Hubs
15 Comments1 Solution969 ViewsLast Modified:
Hi there,
I've a cisco router that ive configured as a DMVPN and there are other spokes that connect to this DMVPN. Now, there is a client who only has IPSec configured at their end and they want to connect to this VPN tunnel. From my understanding, it wont work because in order for them to connect to our network, they need DMVPN client configuration on their cisco router ? Right ?
Now, am thinking if i create a simple IPSec tunnel on my existing router, will it cause any conflict with the existing DMVPN tunnel. In short, can a separate IPSec tunnel coexist with a DMVPN tunnel... Configuration is given below.

VPN-Hub#sh running-config
Building configuration...
 
Current configuration : 6303 bytes
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname VPN-Hub
!
boot-start-marker
boot system flash c1841-advipservicesk9-mz.124-18.bin
boot-end-marker
!
no logging console
enable secret 5 xxx
!
no aaa new-model
ip cef
!
!
!
!
no ip domain lookup
ip auth-proxy max-nodata-conns 3
ip admission max-nodata-conns 3
!
!
!
username admin privilege 15 password 0 xxx
!
!
!
!
crypto isakmp policy 15
 encr aes
 hash md5
 authentication pre-share
 group 2
crypto isakmp key xxxx address 0.0.0.0 0.0.0.0
!
!
crypto ipsec transform-set tset esp-aes
 mode transport
!
crypto ipsec profile cisco
 set transform-set tset
!
!
!
!
interface Tunnel0
 ip address 172.20.1.1 255.255.0.0
 no ip redirects
 ip mtu 1400
 ip nhrp authentication xxx
 ip nhrp map multicast dynamic
 ip nhrp network-id 1
 ip tcp adjust-mss 1360
 tunnel source x.x.x.x
 tunnel mode gre multipoint
 tunnel key 1
 tunnel protection ipsec profile cisco
!
interface FastEthernet0/0
 ip address x.x.x.x 255.255.255.224
 duplex auto
 speed auto
!
interface FastEthernet0/1
 ip address 172.16.0.194 255.255.255.248
 duplex auto
 speed auto
!
interface FastEthernet0/0/0
!
interface FastEthernet0/0/1
!
interface FastEthernet0/0/2
!
interface FastEthernet0/0/3
 switchport mode trunk
!
interface Vlan1
 no ip address
!
router eigrp 2
 network 172.16.0.192 0.0.0.7
 network 172.20.0.0
 distance eigrp 180 180
 no auto-summary
!
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 x.x.x.x
 
!
ip http server
no ip http secure-server
!
!
!
control-plane
!
!
!
line con 0
line aux 0
line vty 0 4
 login local
!
scheduler allocate 20000 1000
end
ASKER CERTIFIED SOLUTION
Join our community to see this answer!
Unlock 1 Answer and 15 Comments.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 1 Answer and 15 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros