dmvpn tunnels with two isps on single spoke using nat

James Smith
James Smith used Ask the Experts™
on
Looking for a dmvpn config with two isps on single spoke behind a ASA (nat).  
Basically I have DMVPN working right now off of Primary ISP, but I would like to add the secondary ISP for failover.
Has anyone done this with an ASA (Two ISP's are on the ASA)  and a single uplink to the DMVPN router?
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Director of Solutions Consulting
Commented:
If you go through the trouble of getting the NAT to work, the routing coming in will still have to choose one path over the other, so now we are looking at BFD. Suggest you don’t go down that path of pain, sdwan handles this so much easier.
Pete LongTechnical Consultant

Commented:
? The ASA does not support Dynamic Multipoint GRE encapsulation ?

You need a router.

Before I'm shouted at - yes it supports VTI now, but it still does not support DMVPN.
SouljaSr.Net.Eng
Top Expert 2011

Commented:
I'd think you could create a second default router with a higher AD on the ASA. The ASA is just forwarding traffic and is not part of the DMVPN, so it shouldn't be an issue having the ASA in front of the DMVPN router. As for natting, you should be able to create NAT's to the DMVPN router for the ISP2's addressing as well on the ASA.
Ensure you’re charging the right price for your IT

Do you wonder if your IT business is truly profitable or if you should raise your prices? Learn how to calculate your overhead burden using our free interactive tool and use it to determine the right price for your IT services. Start calculating Now!

Steve JenningsSr Manager Cloud Networking Ops

Commented:
I must be missing something . . . redundancy on a DMVPN spoke? I don't see the architectural difficulty.

Are you running BGP throughout the DMVPN?

Have fun!
Steve

PS . . . It's been years since I was on E-E . . . howdy Pete Long and Soulja!
SouljaSr.Net.Eng
Top Expert 2011

Commented:
@Steve

Hey! Me too, I took like a 4 year hiatus.
Pete LongTechnical Consultant

Commented:
Hi Steve :)

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial