cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
421
Views
0
Helpful
2
Replies

Single DMVPN overlayed on multiple clouds

chris.berry.1
Level 1
Level 1

At present I have two DMVPNs in place over the internet. One hub per DMVPN. All spokes and the hubs utilize the internet for the DMVPN. I have one new location that has a metro-ethernet link from it's spoke router to one of the hub routers (this hub router has one interface internet facing and one interface for the private metro LAN to the spoke site). Given this is a private connection, spoke to spoke communication won't be possible, which is fine in this case. My question is - will this "break" anything or cause other issues with the DMVPN's operation? I don't want to create a second DMVPN just for this connection if at all possible. I use route tagging to prevent loops and from sending DMVPN traffic from one VPN to the other. If I create a new DMVPN, I need to modify the tags on all of my spokes.

I suppose I could also just do a separate GRE tunnel with IPsec and not put this on the DMVPN at all. If I add more metro-E sites in the future I could then create another DMVPN for that transport.

Thoughts? Or any alternative recommendations for design?

Thanks,

Chris

2 Replies 2

Hello.

For simplicity and for further scale I would suggest to plan another DMVPN cloud for metro connections.

Regarding two clouds for Internet - I didn't understand the reason, as you may run multiple Hubs per DMVPN cloud.

If you are running EIGRP, then to prevent loops and improve convergence, you may use stub feature (or iWAN EIGRP simplification feature).

PS: new cloud wouldn't break anything unless you mess up with routing or network-id (per cloud it should be unique).

The second DMVPN is for PfR and to distinguish between high level SLA / Quality Internet connections vs. more bulk internet connections as secondary such as cable modem. EIGRP is used and we have route tagging in place to prevent loops. We're going to look into the stub-site feature implementation to simplify things.

Thanks for the advice!

Review Cisco Networking for a $25 gift card