Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.


How can i configure the DMVPN for FR Hub and Spoke topology?

As i do have multiple point to point sub interfaces on the HUB router, so what will be the tunnel source ip address for HUB router...? as all ip addresses are assigned to the subinterfaces of the hub router and actual physical interface dont have any ip... so when i want to configure the tunnle for DMVPN then what will be the tunnel source in this case...?



Hall of Fame Super Gold

Re: DMVPN for FR


In the hub, configure a loopback interface and make sure it is propagated via routing and reachable from the spokes. Use this interface as source for tunnels.

One thing is not clear to me, if you have frame-relay hub and spoke, why do you want to configure DMVPN in first place ?

Re: DMVPN for FR

i did the same thing, configured the loopback interface and advertise in routing protocol...

i want automatic IPSec tunnel set up between all spokes when there is any intresting data which i want to transfer securly... and its just for testing... nothign more...

Hall of Fame Super Gold

Re: DMVPN for FR

Ok, so you want some traffic to be encrypted while other is not.

I would start with the configurations given in the DMVPN paper, particular attention must be given to the NHRP mapping because the tunnel interface at the hub is multipoint and does not know where to send data unless you have the above working.

Re: DMVPN for FR

yes i have defined some of the traffice that should be transfered using the IPSecVPN...

yes, its something like... when spoke has data to send it to the other spoke then NHRP will be the main factor to find out the other spoke ip address with the help of hub...

and because of limitation of IPSecVPN which doesnot support the Muilticast and Broadcast traffic will have to use the GRE and here GRE is multipoint tunneling... so we can have hub and spoke with the IPSec as well i will have support for Multicast and Brodacast traffic also... and most intresting part of this DMVPN is Spoke can have dynamic IP addressing scheam to its interface... so when ever the spoke will up it will get IP address from provider and spoke will register that IP address to the HUB...

much more flexiblity to work out...:)



CreatePlease login to create content