Link to home
Start Free TrialLog in
Avatar of RAMU CH
RAMU CHFlag for India

asked on

DMVPN and GET VPNconcept

Hi,
What is DM VPN and GET VPN  and how to configure. Will you provide a best sample scenario to do this. because i am preparing for CCIE Secuirty..
Will PIX 515E 6.0 Version suppors the above and also confirm the suport compatibilty of ASA for the above technologies

Regards
ramu
Avatar of Garry Glendown
Garry Glendown
Flag of Germany image

Both DMVPN (Dynamic Multipoint VPN) and GET VPN (Group Encrypted Transport) are not implemented in either PIX or ASA, it's only available on Cisco routers.

For devices supporting DMVPN, see this URL: http://www.cisco.com/en/US/partner/prod/collateral/iosswrel/ps6537/ps6586/ps6635/ps6658/data_sheet_c78-468520.html

For devices supporting GET, see this URL: http://www.cisco.com/en/US/partner/prod/collateral/iosswrel/ps6537/ps6586/ps6635/ps7180/product_data_sheet0900aecd80582067.html
DMVPN uses GRE tunnels, which is part of the reason it's not supported on the ASA (as Garry-G pointed out), as the ASA doesn't support GRE.  As the name implies, it sets up and encrypts tunnels dynamically as the need arises for one branch office to talk to another branch office.  Although traffic may still actually pass through the hub or corporate site, the burden of maintaining a whole bunch of individual tunnels, and separate routing entries for each, is reduced, as the tunnels are multipoint and use the same subnet.  Next-Hop Routing Protocol (NHRP) is needed to resolve where to go to get to the desired endpoint.

GET VPN does not use tunnels, and is designed to be used over private WAN networks such as a provider-based MPLS backbone.  Without the tunnels, it has somewhat lower overhead than DMVPN, and is arguably more scalable because of the use of group servers.  But, in general, it's a similar concept.

You will absolutely need to know these for CCIE-Sec.  Not just how to configure but how to troubleshoot as well.



Avatar of RAMU CH

ASKER

Hi,

Thanks for your Info,I am not yet started fully on CCIE,i am above to..

Will you share the Experience of CCIE-Secuirty and help me  where i need  to focus to how to do LAB and written exam..

Pls provide the DMVPN and GET VPN troubleshooting Documnets
Regards
Ramu
Avatar of RAMU CH

ASKER

Hi,

What is the Difference betwwen IPSEC and GRE Tunnels,As i asked in the above , will you pls share the Troubleshoot DOCumnets of DMVPN and GETVPN

Regards
Ramu
ASKER CERTIFIED SOLUTION
Avatar of Garry Glendown
Garry Glendown
Flag of Germany image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of RAMU CH

ASKER

Thanks