05-04-2009 01:49 AM
Is ASA device has the ability to provideDynamic Multipoint VPN so that the topology of the network will be like hop and spoke , instead of adding anew site to each device manually .
05-08-2009 10:39 AM
You can able to configure DMVPN in ASA for hub and spoke topology. Dynamic Multipoint VPN (DMVPN) enables better scaling of large and small IPsec VPNs by combining generic routing encapsulation (GRE) tunnels, IP Security (IPsec) encryption, and Next Hop Resolution Protocol (NHRP) routing. In a hub-and-spoke VPN topology, each spoke has a permanent IPsec tunnel to the hub, but not to the other spokes within the topology. Using NHRP, the hub maintains an NHRP database of the public interface addresses of all the spokes (the clients). Each spoke registers its real address with the hub when it boots. When a spoke needs to send a packet to a destination (private) subnet on another spoke, it queries the NHRP server for the VPN address of the destination spoke. After the source spoke learns the peer address of the target spoke, it initiates a dynamic IPsec tunnel to the target spoke.
05-08-2009 11:39 AM
DMVPN is not supported on ASA's. Although you can pass DMVPN *through* the ASA - which is not the same thing.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide