Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

DMVPN and GET VPNconcept

Posted on 2011-09-12
6
Medium Priority
?
758 Views
Last Modified: 2012-05-12
Hi,
What is DM VPN and GET VPN  and how to configure. Will you provide a best sample scenario to do this. because i am preparing for CCIE Secuirty..
Will PIX 515E 6.0 Version suppors the above and also confirm the suport compatibilty of ASA for the above technologies

Regards
ramu
0
Comment
Question by:RAMU CH
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
6 Comments
 
LVL 18

Expert Comment

by:Garry Glendown
ID: 36522890
Both DMVPN (Dynamic Multipoint VPN) and GET VPN (Group Encrypted Transport) are not implemented in either PIX or ASA, it's only available on Cisco routers.

For devices supporting DMVPN, see this URL: http://www.cisco.com/en/US/partner/prod/collateral/iosswrel/ps6537/ps6586/ps6635/ps6658/data_sheet_c78-468520.html

For devices supporting GET, see this URL: http://www.cisco.com/en/US/partner/prod/collateral/iosswrel/ps6537/ps6586/ps6635/ps7180/product_data_sheet0900aecd80582067.html
0
 
LVL 18

Expert Comment

by:jmeggers
ID: 36524803
DMVPN uses GRE tunnels, which is part of the reason it's not supported on the ASA (as Garry-G pointed out), as the ASA doesn't support GRE.  As the name implies, it sets up and encrypts tunnels dynamically as the need arises for one branch office to talk to another branch office.  Although traffic may still actually pass through the hub or corporate site, the burden of maintaining a whole bunch of individual tunnels, and separate routing entries for each, is reduced, as the tunnels are multipoint and use the same subnet.  Next-Hop Routing Protocol (NHRP) is needed to resolve where to go to get to the desired endpoint.

GET VPN does not use tunnels, and is designed to be used over private WAN networks such as a provider-based MPLS backbone.  Without the tunnels, it has somewhat lower overhead than DMVPN, and is arguably more scalable because of the use of group servers.  But, in general, it's a similar concept.

You will absolutely need to know these for CCIE-Sec.  Not just how to configure but how to troubleshoot as well.



0
 
LVL 1

Author Comment

by:RAMU CH
ID: 36527130
Hi,

Thanks for your Info,I am not yet started fully on CCIE,i am above to..

Will you share the Experience of CCIE-Secuirty and help me  where i need  to focus to how to do LAB and written exam..

Pls provide the DMVPN and GET VPN troubleshooting Documnets
Regards
Ramu
0
VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

 
LVL 1

Author Comment

by:RAMU CH
ID: 36527193
Hi,

What is the Difference betwwen IPSEC and GRE Tunnels,As i asked in the above , will you pls share the Troubleshoot DOCumnets of DMVPN and GETVPN

Regards
Ramu
0
 
LVL 18

Accepted Solution

by:
Garry Glendown earned 2000 total points
ID: 36527437
The two URLs I posted above should be a good start ... anyway, just out of curiosity - what's your current status as far as Cisco knowledge goes? It would appear to me that the knowledge required to get through some of the more "basic" courses like e.g. CCNA or CCNP already go a lot further than this and definitely than CCIE ...

As far as troubleshooting and design go:

DMVPN: http://www.cisco.com/en/US/products/ps6658/products_tech_note09186a0080b2a901.shtml

GET-VPN: http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6525/ps9370/ps7180/GETVPN_DIG_version_1_0_External.pdf (very detailed, 157 pages ...)
0
 
LVL 1

Author Closing Comment

by:RAMU CH
ID: 36715474
Thanks
0

Featured Post

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
Let’s face it: one of the reasons your organization chose a SaaS solution (whether Microsoft Dynamics 365, Netsuite or SAP) is that it is subscription-based. The upkeep is done. Or so you think.
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

715 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question