Ipsec over DSVPN while spokes have no public address

Latest reply: Sep 17, 2018 18:24:27 598 1 11 0

Customer request

1.     Spoke 1 can visit HUB and spoke 2

2.     Spoke can access internet through HQ

Noted: spoke router Wan interface is private address and Firewall deny tunnel traffic in the export.

766573ce6153456894788e7c413d777d

Spoke 1

efc5cc7a3a29494fade2a901466633fc

ip route-static 0.0.0.0 0.0.0.0 Cellular0/0/0

Spoke 2

9e78719e74fb4109bda22c83b646c184

ip route-static 0.0.0.0 0.0.0.0 Cellular0/0/0

Hub

5aa840ad7bb84cc2bf18c3004b689586

transparent.gif Handling Process

Check with customer, finding the firewall block GRE traffic, so we just enable IPSEC in the GRE tunnel.

Display IP route in spoke 1, finding that spoke 2 internal subnet next hop is spoke 2 tunnel address , but both spokes have no public IP they cannot built VPN they visit each other have to through HUB. So we just change the OSPF network type .

Display IP route in spoke, finding that the route to internet next hop is local wan interface but not to HUB tunnel address, so we have to modify the route.

transparent.gif Solution

Create a IPSEC in the GRE tunnel.

ce8f2a885eb8488c8a4475d9d0020a86

Change the OSPF network type.

36db825640be49a3a0d738226bbf40f8

Change the route to internet.

327a1a3b9c4348e5acaf2374963c6398

  • x
  • convention:

Sergio93
Created Sep 17, 2018 18:24:27 Helpful(0) Helpful(0)

Thanks for sharing, very useful :)
  • x
  • convention:

BEST ANSWER! If you think I earn it!
If this post was useful to you, please click the Helpful button and flag my post as a "BEST ANSWER" so others can benefit. Thank you

Reply

Reply
You need to log in to reply to the post Login | Register

Notice Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " Privacy."
If the attachment button is not available, update the Adobe Flash Player to the latest version!
Login and enjoy all the member benefits

Login and enjoy all the member benefits

Login