07-02-2009 04:17 AM - edited 03-04-2019 05:18 AM
Experts,
Need your assistance again. I have a customer who has recently migrated leased lines based WAN with Internet based VPN connectivity.
Part 1 Requirements:
Each site has a primary (ADSL2+) and a secondary (SDSL) connection to the internet. In normal operation encrypted VPN tunnels carry only internet traffic via the SDSL connections to the other sites, all other traffic uses the ADSL2+ connection. This is currently installed and stared working.
Part 2 Requirements:
In the event of SDSL connection failure, they want VPN tunnels to automatically
fallback over ADSL2+ connection, and likewise if ADSL+ connection fail all general traffic should failover to SDSL connection. The VPN-based internet uses GRE/IPSec tunnels with NHRP to a central hub, running OSPF. Neither the SDSL nor the ADSL2+ terminate directly on our routers, but instead are presented via Ethernet from a third-party router in transparent bridge mode (the outside IP address appears on our Ethernet interface). We have tried to manipulate OSPF cost for primary and secondary failover but this isn't working.
Could you please provide your expert knowledge on how to resolve this issue and if possible a configuration would be a great help if anyone has gone through the same type of issue.
Thanks
07-05-2009 12:50 PM
Hello JB,
I'm not sure to have understood everything.
Let's me list :
you should have two DMVPNs clouds using two mGRE tunnels on each remote site router.
By doing so you can adjust ospf cost on a per tunnel basis making a clear hierarchy of paths.
see
http://www.cisco.com/en/US/docs/solutions/Enterprise/WAN_and_MAN/DMVPN_1.html#wp36546
using OSPF and a single DMVPN cloud (a single MGRE IP subnet) with two hubs is not recommended for a primary/secondary solution.
Hope to help
Giuseppe
07-09-2009 04:59 AM
Giuseppe,
Thanks mate. Also, sorry for the delay in replying back.
I will check with my engineers as I believe this is the glitch there my engineers may be missing i.e. dual-DMVPNs with dual subnets.
Could I please ask you to send if you have any config examples of dual-DMVPNs with dual subnets.
Regards,
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide