cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
320
Views
0
Helpful
2
Replies

DMVPN

frosbel
Level 1
Level 1

Hi , I am setting up an MPLS network for a customer with over 500 sites. There will be two core data centres and the others spokes/remote sites. Customer does not trust MPLS core and so wants an additional layer of ipsec security.

I have come up with the best solution as been the DMVPN ( Dynamic Multipoint VPN ). However it only supports OSPF and EIGRP and we are running BGP with the ISP at PE level.

DO YOU KNOW OF A WORK AROUND ON HOW DMVPNs can work with BGP.

Regards.

2 Replies 2

brispin
Level 1
Level 1

I think DMVPNs can work with BGP however there are practical limitations to this. For example, if you have 300 spokes all configured in the same AS, they will need seperate peerings with one another. This will require n(n-1)/2 peerings = 44850 seperate TCP sessions configured. Using DMVPN, BGP will not dynamically create TCP sessions between the spokes. You will still need to apply this configuration manually for each spoke. Configuring full mesh peerings between all your spoke routers effectively eliminates the original benefits offered by DMVPN, as the amount of configuration and maintenance required does not make it an scalable option. For this reason, EIGRP is the recommended protocol to be used with DMVPN.

alistaircowan
Level 1
Level 1

You can run whatever you like over a DMVPN tunnel interface, including BGP. As the previous author mentioned, you may wish to look into scalability issues before making a final decision. There is no reason why you could not run two different routing protocols on your DMVPN network.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: