02-15-2024 09:13 AM
Hello.
The enterprise is replacing DMVPN routers with ASA1100's. ASAs do not support DMVPN.
QUESTION: Must the DMVPNs be replaced with cumbersome-to-erect site-to-site IPsec tunnels, or is there a suggested simpler VPN technology supported with ASA1100's?
Thank you.
Solved! Go to Solution.
02-15-2024 09:15 AM - edited 02-15-2024 09:19 AM
@jmaxwellUSAF dVTI on the hubs and sVTI on the spokes are supported using FTD or ASA image, you can then run a dynamic routing protocol over the tunnels, which is less cumbersome to manage than a crypto map policy based VPN. This mirrors DMVPN for Hub and spoke routing but Full Mesh (spoke-to-spoke) is not supported.
https://secure.cisco.com/secure-firewall/v7.3/docs/dynamic-virtual-template-interface-dvti
02-15-2024 09:15 AM - edited 02-15-2024 09:19 AM
@jmaxwellUSAF dVTI on the hubs and sVTI on the spokes are supported using FTD or ASA image, you can then run a dynamic routing protocol over the tunnels, which is less cumbersome to manage than a crypto map policy based VPN. This mirrors DMVPN for Hub and spoke routing but Full Mesh (spoke-to-spoke) is not supported.
https://secure.cisco.com/secure-firewall/v7.3/docs/dynamic-virtual-template-interface-dvti
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide