cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
403
Views
0
Helpful
6
Replies

IPSec VPN the best one

Mero Cisco
Level 1
Level 1

Hi,

I have got a static ip at server side and dynamic at remote side. I want the IPSec VPN, which one is the best? Please provide me the reference of examples.

Regards,

Mero

Sent from Cisco Technical Support iPhone App

2 Accepted Solutions

Accepted Solutions

Joseph W. Doherty
Hall of Fame
Hall of Fame

Disclaimer

The Author of this posting offers the information contained within this posting without consideration and with the reader's understanding that there's no implied or expressed suitability or fitness for any purpose. Information provided is for informational purposes only and should not be construed as rendering professional advice of any kind. Usage of this posting's information is solely at reader's own risk.

Liability Disclaimer

In no event shall Author be liable for any damages whatsoever (including, without limitation, damages for loss of use, data or profit) arising out of the use or inability to use the posting's information even if Author has been advised of the possibility of such damage.

Posting

DMVPN supports remotes with dynamic IP (using NHRP).

View solution in original post

Ok, with that DMVPN is one option, the most up-to-date solution (FlexVPN) is not possible because that is not supported on Gen1 ISRs (1800, 2800, 3800).

Without the need to have spoke-to-spoke traffic and if you don't plan to use that in the future, I would use VTIs on the spokes and DVTIs on the hub. That's quite easy to configure and scales easily to your amout of spokes.

The third option is EasyVPN. But I woudn't use that any more as the combination of VTI/DVTI gives you more flexibility.

-- 
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni

View solution in original post

6 Replies 6

Joseph W. Doherty
Hall of Fame
Hall of Fame

Disclaimer

The Author of this posting offers the information contained within this posting without consideration and with the reader's understanding that there's no implied or expressed suitability or fitness for any purpose. Information provided is for informational purposes only and should not be construed as rendering professional advice of any kind. Usage of this posting's information is solely at reader's own risk.

Liability Disclaimer

In no event shall Author be liable for any damages whatsoever (including, without limitation, damages for loss of use, data or profit) arising out of the use or inability to use the posting's information even if Author has been advised of the possibility of such damage.

Posting

DMVPN supports remotes with dynamic IP (using NHRP).

Hi,

Is there any other options beside this one?

Regards,

Mero

Sent from Cisco Technical Support iPhone App

As Joseph indicated DMVPN is the current Cisco recommendation when you have dynamically addressed sites.

Sent from Cisco Technical Support iPad App

With this little information it's not possible to suggest the best solution for your environment.

1) How many remotes are you talking about?

2) Do you need spoke-2-spoke traffic?

3) Which VPN-devices do you have on the HQ and on the remote-sites?

4) Or are perhaps only talking about remote that need to connect?

-- 
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni

Mero Cisco
Level 1
Level 1

Hi,

1. About 10
2. No
3. HQ - 3825, 2900, 1841: remote - 1841, 881
4. Remote to HQ

I want to connect through 3G on remote side.

Regards,


Mero

Sent from Cisco Technical Support iPhone App

Ok, with that DMVPN is one option, the most up-to-date solution (FlexVPN) is not possible because that is not supported on Gen1 ISRs (1800, 2800, 3800).

Without the need to have spoke-to-spoke traffic and if you don't plan to use that in the future, I would use VTIs on the spokes and DVTIs on the hub. That's quite easy to configure and scales easily to your amout of spokes.

The third option is EasyVPN. But I woudn't use that any more as the combination of VTI/DVTI gives you more flexibility.

-- 
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni

Review Cisco Networking products for a $25 gift card