DMVPN Confusion


I have a little confustion about DMVPN phase 2, In Phase 2 you can enable 2 spokes to communicate directly to each other...Ok fine BUT We have the same Physical Topology i.e The Hub and Spoke Topology, So we still have to pass through the Hub right? so whats the point in using the Phase 2 then ?? and how come it reduces burden on the HUB? it still does have to proccess all the packets b/w the 2 Spokes.!


Please do clarify thank you

In phase 1, spoke can only

In phase 1, spoke can only setup protected tunnel with hub, so the traffic between spokes will be directed to hub to decryption, then be delivered to destination spoke by encryption again.

In phase 2,  two spoke can dynamically setup protected tunnel between them, so the traffic between them will be delivered to hub by encryption to hub when each spoke has only physical connection with hub, however the hub don't need to decode this encrypted packet, it just forward this packet as other ip packet.

In most of DMVPN deployment scenarios, both hub and spoke are connected to internet, so the scenario you mentioned is very rare.


Very well said sir, I had

And another issue is that they are also using # ip nhrp Shortcut on spokes, They have a HUB and spoke toplogy over the MPLS cloud, i think this is phase 3 DMVPN, but can you explain why this command is there & what does it do? 

And another issue is that they are also using # ip nhrp Shortcut on spokes, They have a HUB and spoke toplogy over the MPLS cloud, i think this is phase 3 DMVPN, but can you explain why this command is there & what does it do?

Hi,Using phase 2, spoke needs


Using phase 2, spoke needs to communicate once with the Hub router to get nhrp record for the spoke it would like to communicate to. If you perform a traceroute between the spokes with phase 1 and phase 2 you will see the difference between the packetflows.

If you have static IPs on all routers, you can map nhrp records on all hosts and have no hub topology with full-mesh.

Thank You sir for your

and they are using a Hub and spoke topology  over MPLS so it cant be full mesh as its not connected over the internet cloud


If each site is connected

If each site is connected over MPLS and the traffic need to be protected, GETVPN is better solution than DMVPN

Ok great thanks il look into

but can you tell me something about phase 3 of DMVPN? Why and when would you use it

