| Hi Kings, If you are running DMVPN phase 3, and two spokes are behind NAT with PAT, then it's basically impossible to have spoke-spoke traffic, so traffic between those spokes is still going through the hub. If you check the configuration guide (the third link in your mail), under the Restrictions for DMVPN: Dynamic Tunnels between spokes behind a nat device, it also states: "If one spoke is behind one NAT device and another different spoke is behind another NAT device, and Peer Address Translation (PAT) is the type of NAT used on both NAT devices, then a session initiated between the two spokes cannot be established." So if you're on a PAT'ed device, it would be impossible, with NAT (without firewalling on the NAT device) of course, traffic would occur, as the translation is already active.. HTH Pieter-Jan PS: Who is going to attend Cisco Live in London in January? On 3 okt 2010, at 10:08, Kingsley Charles wrote: Hi all --- Nefkens Advies Enk 26 4214 DD Vuren The Netherlands Tel: +31 183 634730 Fax: +31 183 690113 Cell: +31 654 323221 Email: [email protected] |
_______________________________________________ For more information regarding industry leading CCIE Lab training, please visit www.ipexpert.com
