Ipsec over DSVPN while spokes have no public address

Latest reply: Sep 17, 2018 18:24:27 600 1 11 0

Customer request

1.     Spoke 1 can visit HUB and spoke 2

2.     Spoke can access internet through HQ

Noted: spoke router Wan interface is private address and Firewall deny tunnel traffic in the export.


Spoke 1


ip route-static Cellular0/0/0

Spoke 2


ip route-static Cellular0/0/0



transparent.gif Handling Process

Check with customer, finding the firewall block GRE traffic, so we just enable IPSEC in the GRE tunnel.

Display IP route in spoke 1, finding that spoke 2 internal subnet next hop is spoke 2 tunnel address , but both spokes have no public IP they cannot built VPN they visit each other have to through HUB. So we just change the OSPF network type .

Display IP route in spoke, finding that the route to internet next hop is local wan interface but not to HUB tunnel address, so we have to modify the route.

transparent.gif Solution

Create a IPSEC in the GRE tunnel.


Change the OSPF network type.


Change the route to internet.


  • x
  • convention:

Created Sep 17, 2018 18:24:27 Helpful(0) Helpful(0)

Thanks for sharing, very useful :)
  • x
  • convention:

BEST ANSWER! If you think I earn it!
If this post was useful to you, please click the Helpful button and flag my post as a "BEST ANSWER" so others can benefit. Thank you


You need to log in to reply to the post Login | Register

Notice Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " Privacy."
If the attachment button is not available, update the Adobe Flash Player to the latest version!
Login and enjoy all the member benefits

Login and enjoy all the member benefits