This blog explores data science and networking, combining theoretical concepts with practical implementations. Topics include routing protocols, network operations, and data-driven problem solving, presented with clarity and reproducibility in mind.
Thursday, November 28, 2024
Dual Hub Dual DMVPN Setup: Comparing Old vs New Cisco IOS Versions
Tuesday, November 26, 2024
Setting Up Dual Hub DMVPNs: Redundancy Made Easy with Modern Cisco IOS
Dual Hub DMVPN: Complete Configuration & Optimization Guide
๐ Table of Contents
๐ Introduction
Dynamic Multipoint Virtual Private Network (DMVPN) is a scalable VPN solution that allows secure communication over public networks. When combined with a dual hub architecture, it provides high availability and redundancy.
๐ Why Dual Hub DMVPN?
- High Availability
- Fault Tolerance
- Load Sharing
- Reduced Downtime
๐ฝ Expand: Real-world Scenario
If Hub1 fails, spokes automatically reroute traffic to Hub2, ensuring uninterrupted service.
๐งฉ Deployment Models
1. Single DMVPN Cloud
- One tunnel interface
- Two hubs (dual NHS)
- Simple design
2. Dual DMVPN Cloud
- Two tunnel interfaces
- Separate routing domains
- Advanced traffic control
๐ก Single DMVPN Configuration
In this model, all routers belong to the same DMVPN cloud.
Configuration Code
interface Tunnel0 ip address 192.168.1.2 255.255.255.0 tunnel source GigabitEthernet0/0 tunnel mode gre multipoint tunnel key 100 tunnel protection ipsec profile IPSEC_PROFILE ip nhrp map 192.168.1.1 HUB1_PUBLIC_IP ip nhrp map 192.168.1.3 HUB2_PUBLIC_IP ip nhrp network-id 1 ip nhrp nhs 192.168.1.1 ip nhrp nhs 192.168.1.3
๐ฝ Expand Explanation
NHRP maps logical tunnel IPs to physical IPs. Dual NHS ensures redundancy.
๐ Dual DMVPN Configuration
Each spoke connects to two hubs using separate tunnels.
interface Tunnel0 ip address 192.168.1.2 255.255.255.0 tunnel source GigabitEthernet0/0 tunnel key 100 ip nhrp nhs 192.168.1.1 interface Tunnel1 ip address 192.168.2.2 255.255.255.0 tunnel source GigabitEthernet0/1 tunnel key 200 ip nhrp nhs 192.168.2.1
๐ฝ Expand Benefits
Provides granular control and allows traffic engineering using routing metrics.
๐ Routing Protocols
EIGRP
- Easy metric manipulation
- Fast convergence
OSPF
- More complex
- Requires tuning
๐ฝ Expand Deep Comparison
EIGRP allows delay/bandwidth tuning, while OSPF uses cost-based routing requiring more manual adjustments.
⚙️ Cisco IOS 15.9 Enhancements
- Improved NHRP convergence
- DMVPN Phase 3 optimization
- Enhanced IPsec encryption
- Advanced logging tools
๐ป CLI Output Examples
Show DMVPN Status
show dmvpn Legend: Attrb --> S - Static, D - Dynamic Tunnel0, NHRP Details Type:Spoke, NHRP Peers:2 Peer NBMA Addr: 10.1.1.1 Peer NBMA Addr: 10.1.1.2
Debug Output
*Mar 1 12:00:01: NHRP: Resolution request sent *Mar 1 12:00:02: NHRP: Resolution reply received
๐ฝ Expand CLI Explanation
Shows tunnel peers and NHRP resolution process.
๐ฏ Key Takeaways
- Dual Hub DMVPN ensures redundancy
- Single cloud = simple, less control
- Dual cloud = complex, more control
- EIGRP preferred for flexibility
- IOS 15.9 improves performance significantly
๐ Conclusion
Dual hub DMVPN designs provide scalable, resilient, and efficient networking solutions. Choosing between single and dual DMVPN depends on complexity vs control requirements.
Featured Post
How HMT Watches Lost the Time: A Deep Dive into Disruptive Innovation Blindness in Indian Manufacturing
The Rise and Fall of HMT Watches: A Story of Brand Dominance and Disruptive Innovation Blindness The Rise and Fal...