i am just scratching my head about the following behaviour, and i am not sure if i understood it right.
When i am using eigrp summaries at my spokes , the next-hop for the summary route is always the NHRP-Address of the Hub.
Dynmic spoke-to-spoke tunnels are succesfully created, connectivity is there.
NHRP injects "NHRP" routes for the routes that are "summarized" , using the next-hop of the spoke that advertises the summary. Looks fine, i think thats the expected bahaviour.
But why does the hub does not "redirect" queries for the summary route to the "real" Spoke-Address ?
I have a DMVPN Topology with EIGRP used as routing protocol.
Tunnel 2 with IPs used 10.xx.y.0/24 , Hub uses 10.xx.y.254 , Spoke1 uses 10.xx.y.8 , Spoke uses 10.xx.y.111
Spoke1 "hosts" various subnets out of the 10.222.x.x/16 range. Spoke1 asdvertises a EIGRP summary 10.222.0.0/16.
Routing table from SPOKE2 :
! <--- Summary w/ Hub as next-hop D 10.222.0.0/16 [90/10296320] via 10.xx.y.254, 01:44:43, Tunnel2 <--- Summary w/ Hub as next-hop
! <-- summarized routes w/ Spoke1 as next-hop , injected by NHRP
H 10.222.20.0/24 [250/255] via 10.xx.y.8, 01:05:14, Tunnel2 H 10.222.22.0/24 [250/255] via 10.xx.y.8, 01:05:17, Tunnel2 H 10.222.30.0/24 [250/255] via 10.xx.y.8, 01:05:18, Tunnel2 H 10.222.31.0/24 [250/255] via 10.xx.y.8, 01:05:07, Tunnel2 H 10.222.40.0/24 [250/255] via 10.xx.y.8, 01:05:16, Tunnel2 H 10.222.80.0/24 [250/255] via 10.xx.y.8, 01:04:26, Tunnel2 SPOKE2#
I wonder if this the expected behaviour ?
... View more
many thanks for the opprtunity to ask some questions about DMVPN design .
1. Recommended Routing-Protocol :
Is there a recommendation which protocol to choose in a DMVPN Ph3 environment ?
I thought, EIGRP and BGP would be the weapon of choice.
Some say , OSPF is possible, but not recommended ( configuration and troubleshooting might be challenging ).
My knowledge is taken from some elder Cisco-docs , dont know if this is still valid.
2. Best Practice during a Migration :
2.a Tunnel Protection , Migration from IKEv1 to IKEv2
We are trying to migrate an existing DMVPN Deployment. One step will be the replacement of the EOL-Routers step by step.
Since we have to change the configuartion during this replacement ( IOS to IOS-XE e.g. ) , we would like to move to IKEv2 in general.
What is the recommendation in such a "mixed environment" ?
Is it possibe to migrate without changing the topology , means can i use IKEv1 and IKEv2 under the same tunnel-interface ?
If this is not possible, do i have to build seperate topologies for IKEv1 and IKEv2 ? ( diffenrent tunnel-interfaces , different hubs etc. ).
Many thanks in advance.
... View more