DMVPN configuration example

Hi
1.I am looking for config sample for spoke -to-spoke directly

2.I am looking for config sample for spoke -to-spoke VIA hub

Thanks in ADVANCE
alimohammed72Asked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

asavenerCommented:
You might also want to investigate the new technology GET VPN.
0
Webinar: Miercom Evaluates Wi-Fi Security

It's not just about Wi-Fi connectivity anymore. A wireless security breach can cost your business large amounts of time, trouble, and expense. Plus, hear first-hand from Miercom how WatchGuard's Wi-Fi security stacks up against the competition in our upcoming webinar!

alimohammed72Author Commented:
this is good for sopke to spoke via HUB but I am looking for SPOKE-SPOKE directly
0
asavenerCommented:
The second link shows that:

"Background Theory  

The feature works according to the following rules.  

*Each spoke has a permanent IPSec tunnel to the hub, not to the other spokes within the network. Each spoke registers as clients of the NHRP server.
 
*When a spoke needs to send a packet to a destination (private) subnet on another spoke, it queries the NHRP server for the real (outside) address of the destination (target) spoke.
 
*After the originating spoke learns the peer address of the target spoke, it can initiate a dynamic IPSec tunnel to the target spoke.
 
*The spoke-to-spoke tunnel is built over the multipoint GRE (mGRE) interface.
 
*The spoke-to-spoke links are established on demand whenever there is traffic between the spokes. Thereafter, packets are able to bypass the hub and use the spoke-to-spoke tunnel. "
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
harbor235Commented:
Here is my working config for spoke to spoke,

HUB using EIGRP)

crypto isakmp policy 1            
 authentication pre-share            
crypto isakmp key dmvpn address 0.0.0.0            
!            
crypto ipsec transform-set trans2 esp-3des esp-sha-hmac            
mode transport            
!            
crypto ipsec profile dmvpnprof            
 set transform-set trans2            

interface Tunnel0                  
 bandwidth 1000                  
 ip address 172.16.1.3 255.255.255.0                  
 ip mtu 1400                  
 ip nhrp authentication donttell                  
 ip nhrp map multicast dynamic                  
 ip nhrp network-id 99                  
 ip nhrp holdtime 300                  
 no ip route-cache                  
 no ip split-horizon eigrp 200                  
 ip tcp adjust-mss 1360                  
 delay 1000                  
 tunnel source <add physical interface here>                  
 tunnel mode gre multipoint                  
 tunnel key 12345                  
 tunnel protection ipsec profile dmvpnprof      

SPOKE X;

crypto isakmp policy 1                              
 authentication pre-share                              
crypto isakmp key dmvpn address 0.0.0.0                              
!                              
crypto ipsec transform-set trans2 esp-3des esp-sha-hmac                              
mode transport                              
!                              
crypto ipsec profile dmvpnprof                              
 set transform-set trans2                              
!                              
interface Tunnel0                              
 bandwidth 1000                              
 ip address 172.16.1.6 255.255.255.0                              
 ip mtu 1400                              
 ip nhrp authentication donttell                              
 ip nhrp map multicast dynamic                              
 ip nhrp map 172.16.1.3 201.1.36.3                              
 ip nhrp map multicast 201.1.36.3                              
 ip nhrp nhs 172.16.1.3                              
 ip nhrp network-id 99                              
 ip nhrp holdtime 300                              
 ip tcp adjust-mss 1360                              
 delay 1000                              
 tunnel source <add physical interface>                              
 tunnel mode gre multipoint                              
 tunnel key 12345                              
 tunnel protection ipsec profile dmvpnprof                              

harbor235 ;}
            
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Networking Protocols

From novice to tech pro — start learning today.