Link to home
Start Free TrialLog in
Avatar of James Smith
James SmithFlag for United States of America

asked on

dmvpn tunnels with two isps on single spoke using nat

Looking for a dmvpn config with two isps on single spoke behind a ASA (nat).  
Basically I have DMVPN working right now off of Primary ISP, but I would like to add the secondary ISP for failover.
Has anyone done this with an ASA (Two ISP's are on the ASA)  and a single uplink to the DMVPN router?
ASKER CERTIFIED SOLUTION
Avatar of Aaron Tomosky
Aaron Tomosky
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
? The ASA does not support Dynamic Multipoint GRE encapsulation ?

You need a router.

Before I'm shouted at - yes it supports VTI now, but it still does not support DMVPN.
I'd think you could create a second default router with a higher AD on the ASA. The ASA is just forwarding traffic and is not part of the DMVPN, so it shouldn't be an issue having the ASA in front of the DMVPN router. As for natting, you should be able to create NAT's to the DMVPN router for the ISP2's addressing as well on the ASA.
Avatar of Steve Jennings
Steve Jennings

I must be missing something . . . redundancy on a DMVPN spoke? I don't see the architectural difficulty.

Are you running BGP throughout the DMVPN?

Have fun!
Steve

PS . . . It's been years since I was on E-E . . . howdy Pete Long and Soulja!
@Steve

Hey! Me too, I took like a 4 year hiatus.
Hi Steve :)