In continuation of T1186
we need to have spokes behind NAT working
Description
Description
Details
Details
- Difficulty level
- Unknown (require assessment)
- Version
- -
- Why the issue appeared?
- Will be filled on close
- Is it a breaking change?
- Perfectly compatible
- Issue type
- Improvement (missing useful functionality)
Related Objects
Related Objects
- Mentioned Here
- T1186: Setup DMVPN cannot work
Event Timeline
Comment Actions
Following this issue request https://sourceforge.net/p/opennhrp/support-requests/3/ we need to use transport mode instead of a tunnel. Was tested on AWS node and it looks working even with selector remote_ts = dynamic[gre]
Comment Actions
DMVPN Spokes work properly behind a NAT if we use transport mode instead of tunnel. e.g.
set vpn ipsec esp-group ESP-HUB mode transport
So I think we need to add this info to docs.vyos.io and close this Feature Request
Comment Actions
PR with changed types in docs https://github.com/vyos/vyos-documentation/pull/380
ESP transport mode works properly on Cisco Router and VyOS routers together.