cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
312
Views
10
Helpful
5
Replies

what is the use cases to choose/prefer one of the below WAN VPN tech over other

Ibrahim Jamil
Level 6
Level 6

Hi

 

what is the use cases to choose/prefer one of the below VPN tech over other

 

 

DMVPN :as per my knowledge , DMVPN works over internet

 

GETVPN

 

FLEXvPN

5 Replies 5

Hi,

 

Try page 25 on this cisco live presentation

 

Ultimately:

 

DMVPN/FlexVPN - both work over the internet.

DMVPN is preferred for large scale Hub-Spoke + Spoke-to-Spoke

FlexVPN is preferred for Hub-Spoke, IOT and remote access

GETVPN - Private IP network only (MPLS), preserves IP header, so not routable on internet.

 

What is your use case? perhaps we can identify which best fits your requirements

HTH

thanks RJI

 

Will post things here later , stay tuned :) ,

 

so far we choosed DMVPN  with dual hub , 2 x 2921 routers sits in DMZ Behind Firewall

 

any online document

 

thanks

 

 

 

Hello Raji

 

thanks for usefull links

 

I need config example while the Dual VPN routers sits in DMZ behind  dual firewalls , non-of the above mentioned that

 

 

thanks

I doubt there are any/many post out there matching your exact scenario, but at a minimum you will need to allow the traffic on your firewall:

If not natting - UDP 500 and ESP
If natting UDP 500 and UDP 4500 (ESP would be encapsulated inside UDP 4500, so you don't specifically need to allow that).

If natting, when it comes to the configuration of the spokes you'd need to specify the nbma address of the Hub to be the natted IP address.

HTH
Review Cisco Networking products for a $25 gift card