cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1434
Views
1
Helpful
3
Replies

DMVPN or GETVPN

bijbalaktn
Level 1
Level 1

Team - We have a customer who is running GET VPN on  MPLS link from DC to spoke.  They are heading towards a network refresh.    We thought of suggesting IWAN to them.  DMVPN is one of the 4 pillars of IWAN.  Can we ask the customer to go for DMVPN instead of GetVPN.  Or should it be done in any  other way.  Any Cons , please highlight. 

Thanks

1 Accepted Solution

Accepted Solutions

Frank DeNofa
Cisco Employee
Cisco Employee

bijbalaktn,

When you say "network refresh," what does that entail? We will still be using MPLS as our transport network? 

Either GETVPN or DMVPN will be an appropriate solution over an MPLS network. Two benefits of GETVPN include slightly less encapsulation overhead (as it is just ESP encapsulation without GRE) and the lack of requirement for an overlay routing protocol. That said, when comparing DMVPN and GETVPN, most people are much more comfortable with DMVPN which is a benefit in and of itself. Additionally, if you are considering an IWAN solution then DMVPN is a requirement per the IWAN CVD.

In short, either solution should work and it's really up to you; personally I'm a big fan of both. If you're comfortable with GETVPN and it has been working for you, it may be best to stick with that. However, DMVPN should work fine for you as well.

HTH,

Frank

View solution in original post

3 Replies 3

Frank DeNofa
Cisco Employee
Cisco Employee

bijbalaktn,

When you say "network refresh," what does that entail? We will still be using MPLS as our transport network? 

Either GETVPN or DMVPN will be an appropriate solution over an MPLS network. Two benefits of GETVPN include slightly less encapsulation overhead (as it is just ESP encapsulation without GRE) and the lack of requirement for an overlay routing protocol. That said, when comparing DMVPN and GETVPN, most people are much more comfortable with DMVPN which is a benefit in and of itself. Additionally, if you are considering an IWAN solution then DMVPN is a requirement per the IWAN CVD.

In short, either solution should work and it's really up to you; personally I'm a big fan of both. If you're comfortable with GETVPN and it has been working for you, it may be best to stick with that. However, DMVPN should work fine for you as well.

HTH,

Frank

Thanks Frank, Network refresh meant only changing the HW. The transport remains MPLS. 

Since its IWAN that we offer, as you said, we have to go for DMVPN.   Appreciate your inputs.

Cheers,

B

Glad to help. Here's a link to the IWAN CVD which I'm sure you'll become more than familiar with if you haven't already. Good luck!

http://www.cisco.com/c/dam/en/us/td/docs/solutions/CVD/Feb2016/CVD-IWANDesignGuide-FEB16.pdf