Every year or two someone writes me an email about a DMVPN article I wrote back in 2017 when I was trying to figure out issues in large mobile WANs over 3G/LTE (some as backup, some as only link).
It's kinda wild how some things don't really change... tunneling and NAT continue to deliver and entertain.
DMVPN-over-Mobile Blues
It all started a while ago with a log message found on the hub of a large DMVPN/IPSEC deployment over mobile Internet connections. Given the increasing number of deployments that use the Internet as a cheaper, faster WAN for either primary or backup, I thought it would be useful to document the problems and the two main solutions.