DMVPN

Unanswered Question
Jan 16th, 2009

I am building a VPN architecture that connects to 2 separate NOCS. I want to have half my offices point to 1 NOC and the other half point to the other and have each NOC be the backup Hub for the other. Is this achievable with DMVPN

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
bob.bartlett Sat, 01/17/2009 - 17:56

I think i made a mistake in stating this. I want to design this so that one NOC is the primary and the other NOC the backup? Is that possible? So when you build your DMVPN the primary NOC for one group is the west coast NOC and the backup is the east coast and opposite for the other coast.

dominic.caron Mon, 01/19/2009 - 07:02

The two hub (NOC) have to be up at the same time. If you want to split the load like that, the only way to go is with routing protocol.

If you look at the Dual Hub - Single DMVPN Layout explanations, you can read this :

The dynamic routing protocol will not run over the dynamic IPsec+mGRE links between spokes. Since the spoke routers are routing neighbors with the hub routers over the same mGRE tunnel interface, you cannot use link or interfaces differences (like metric, cost, delay, or bandwidth) to modify the dynamic routing protocol metrics to prefer one hub over the other hub when they are both up.

Now int the Dual Hub - Dual DMVPN Layout definition :

Since the spoke routers are routing neighbors with both hub routers over the two GRE tunnel interfaces, you can use interface configuration differences (such as bandwidth, cost and delay) to modify the dynamic routing protocol metrics to prefer one hub over the other hub when they are both up.

You'll have to try it.

Actions

This Discussion