01-28-2025 04:23 AM
Hi All
I have about 20 sites that are on MPLS, we have a backup to this by creating GRE tunnels on the backup router, it is very cumbersome as we have these going over IPsec tunnels on our firewalls, so its not efficient at all.
We do not have SDWAN and have no plans at the moment to move to it.
What are our best options here, I was thinking DMVPN?
Are lots of people still using DMVPN?
Cheers
01-28-2025 04:29 AM
If you have mpls why ypu are looking for dmvpn over mpls ?
What is ypur requirements
MHM
01-28-2025 04:37 AM
Hi, each site has 1 MPLS connection, this is then backed up via Internet.
01-28-2025 05:04 AM
three option
1- make SP use import/export target to make all site connect to each other
2- using DMVPN or GETVPN
3- using FlexVPN <<- this new
MHM
01-28-2025 05:02 AM
"Are lots of people still using DMVPN?"
Cannot say, but DMVPN would seem to be a suitable option.
(In the distance past, have used DMVPN as a parallel path to private WAN cloud. Worked very well. So well, private WAN offered very little benefit over it, although much more costly.)
01-28-2025 09:18 PM
Hello
You could in theory used both mpls and internet for DMVPN, (single/dual hub & dual cloud design) running ebgp over it for a true resilient dynamic dmvpn network
However just introducing it for a backup solution would be also a viable alternative, it wont care what underlay you are using, it will work just like any other used for it.
You would need to specify hub(s) for the DMVPN network so the spokes sites can registrar towards and to enable dynamic tunnel between themselves.(phase2/3) and then depending on what routing process you use (BGP) , it can be tweaked so path preference is via your main mpls path.
02-10-2025 02:16 AM
Hi Paul,
Any thoughts on what protocol to use, we use OSPF currently on our WAN, single area.
I see the preferred option seems to be EIGRP for DMVPN, what are your thoughts ?
Cheers
Carl
02-13-2025 02:52 AM - edited 02-15-2025 02:50 AM
Notes
1- Asa/ftd not support dmvpn & FlexVPN
2- always cisco prefer use with dmvpn
A- eigrp
B- bgp (ibgp or ebgp)
MHM
02-15-2025 02:50 AM
02-13-2025 01:49 PM - edited 02-13-2025 01:56 PM
Hello
@carl_townshend wrote:
Hi Paul,
Any thoughts on what protocol to use, we use OSPF currently on our WAN, single area.
I see the preferred option seems to be EIGRP for DMVPN, what are your thoughts ?
MPLS connection, this is then backed up via Internet.
Edited- (just noticed you also have a separate DIA at each site
FYI -each sites ce/pe subnet will need to be reachable to each other site (via the isp mpls bb) so NBMA reachability of DMVPN can be obtained for the hub/spoke tunnels
Once that is achieved then it will just a matter of creating the dmvpn overlay network and in this instance it seams a single/dual hub single dual cloud phase 2/3 design would be applicable
Additionally my understanding is the same as you in that eigrp is the preferred igp for dmvpn but I would say bgp is also preferable, However if you wish to run ospf then that’s applicable to, but you will need to use a broadcast network type on the tunnels (as p2p-p2m is not applicable ) also making sure the hub(s) are the selected DRs for the DMVPN and ALL spokes are DRothers
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide