DMVPN
DMVPN
Candidates
Johnny Bass
CCIE #6458
BRKCCIE-3003
@CCIE6458
BRKCCIE-3003 - DMVPN for Route & Switching CCIE Candidates © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public
Why Are We Here?
• Show of hands, how many of you are currently supporting DMVPN?
• Show of hands, how many of you actually have configured DMVPN on a router?
• Show of hands, how many of you heard of DMVPN before it was on the v5.0
Blueprint?
R2 R4
R3
R2 R4
R3
• Because DMVPN Phase 3 does not require the hub to preserve next-hop values in routing
updates, summarization of routing protocol updates from hub to spokes is allowed.
• You can even configure the hub router to advertise only a default route to its spoke
routers.
• The spokes don’t need to have an individual route with an IP next hop of the tunnel IP
address of the remote spoke for the networks behind all the other spokes.
• The spokes can use summarized routes with an IP next hop of the tunnel IP address of
the hub and still be able to build spoke-to-spoke tunnels.
• This summarization possibility significantly improves network scalability.
• In a DMVPN Phase 3 network, separate regional DMVPN networks can be connected into
a single hierarchical DMVPN network.
Tunnel1234
R2 R4
R3
• Static Spokes:
• OSPF can only neighbor to Hub
• EIGRP can neighbor with static neighbor statements
• eBGP can form peering relationships by using either ebgp-multihop ot TTL security
E1/0 .2 E1/0 .1
R2 E1/1 .2 E1/1 .1 R1
E0/2 .2 E0/2 .1
E0/3 .2 10.1.26.0/24 10.1.16.0/24 E0/3 .2
Tu91 .2 Tu91 .1
E0/1 .60 E0/0 .60
14.1.62.0/24 14.1.111.0/24
SW6
EIGRP EIGRP
14.1.112.0/24
E0/1 .6 AS 10 P AS 10 E0/1 .11
14.1.56.0/24
OSPF
CE Area 0 CE E0/0 .11 E0/0 .12
E0/0 .5 E0/0 .6 R12
R5 R6 R11
E0/0 .5 E0/0 .6 E0/0 .11 E0/0 .12
14.1.34.0/24
VL105 .110 AS 100 VL206 .120 DMVPN VL103 .130 VL204 .140
AS 10 Secure
DMVPN VL34 .130 VL34 .140
SW1 VL108 .110 VL207 .120 SW2 SW3 SW4
VL107 .110 .1 14.1.91.0/24 .1 VL44 .140
14.1.108.0/24 VL208 .120 VL33 .130
SP2 BGP SP1 BGP
14.1.107.0/24 14.1.208.0/24 14.1.33.0/24 14.1.44.0/24
AS 20002 AS 20001
14.1.207.0/24 .1 .1 .1 .1 EIGRP ENG E0/0 .14
E0/0 .8 E0/0 .13 AS 100
E0/0 .7
E0/0 .8
E0/0 .7 Engineering
R8 R13 R14
R7
E0/1 14.1.7.1/24 E0/1 14.1.8.1/24 E0/1 14.1.13.1/24 E0/1 14.1.14.1/24
Production
CE CE
Branch 1 Tu91 .9 Tu91 .10 Branch 2
S1/0 .2 E0/0 .2 E0/0 .2 S1/0 .2
R9 R10
E0/1 14.1.9.1/24 E0/1 14.1.10.1/24
EIGRP EIGRP
DMVPN DMVPN
AS 10 AS 10
BGP AS 65009 BGP AS 65010
E1/0 .2 E1/0 .1
R2 E1/1 .2 E1/1 .1 R1
E0/2 .2 E0/2 .1
E0/3 .2 10.1.26.0/24 10.1.16.0/24 E0/3 .2
Tu91 .2 Tu91 .1
E0/1 .60 E0/0 .60
14.1.62.0/24 14.1.111.0/24
SW6
EIGRP EIGRP
14.1.112.0/24
E0/1 .6 AS 10 P AS 10 E0/1 .11
14.1.56.0/24
OSPF
CE Area 0 CE E0/0 .11 E0/0 .12
E0/0 .5 E0/0 .6 R12
R5 R6 R11
E0/0 .5 E0/0 .6 E0/0 .11 E0/0 .12
14.1.34.0/24
VL105 .110 AS 100 VL206 .120 DMVPN VL103 .130 VL204 .140
AS 10 Secure
DMVPN VL34 .130 VL34 .140
SW1 VL108 .110 VL207 .120 SW2 SW3 SW4
VL107 .110 .1 14.1.91.0/24 .1 VL44 .140
14.1.108.0/24 VL208 .120 VL33 .130
SP2 BGP SP1 BGP
14.1.107.0/24 14.1.208.0/24 14.1.33.0/24 14.1.44.0/24
AS 20002 AS 20001
14.1.207.0/24 .1 .1 .1 .1 EIGRP ENG E0/0 .14
E0/0 .8 E0/0 .13 AS 100
E0/0 .7
E0/0 .8
E0/0 .7 Engineering
R8 R13 R14
R7
E0/1 14.1.7.1/24 E0/1 14.1.8.1/24 E0/1 14.1.13.1/24 E0/1 14.1.14.1/24
Production
CE CE
Branch 1 Tu91 .9 Tu91 .10 Branch 2
S1/0 .2 E0/0 .2 E0/0 .2 S1/0 .2
R9 R10
E0/1 14.1.9.1/24 E0/1 14.1.10.1/24
EIGRP EIGRP
DMVPN DMVPN
AS 10 AS 10
BGP AS 65009 BGP AS 65010
• Configure the mGRE Tunnel91 interfaces on R1, R2, R9, and R10.
• Supply IPv4 addresses for all required tunnel interfaces according to the “MP-BGP MPLS VRFB Topology” diagram.
• Configure R9 as the IPv4 NHRP NHS for the DMVPN spokes R1, R2, and R10.
• Supply the NHRP NHS mapping for unicast IPv4 on R1, R2, and R10. Do not configure any NHRP mapping for unicast IPv4 traffic
on R9.
• Provide static mapping for the IPv4 multicast and broadcast traffic on R1, R2, and R10.
• Configure the IPsec ISAKMP policy on R1, R2, R9, and R10 according to the following specifications:
Parameter Value
• Apply the IPsec profile on the Tunnel91 interfaces on R1, R2, R9, and R10.
• You can submit an entry for more than one of your “favorite” speakers
• Don’t forget to follow @CiscoLive and @CiscoPress
• View the official rules at http://bit.ly/CLUSwin
58