Solved

DMVPN and GET VPNconcept

Posted on 2011-09-12
6
739 Views
Last Modified: 2012-05-12
Hi,
What is DM VPN and GET VPN  and how to configure. Will you provide a best sample scenario to do this. because i am preparing for CCIE Secuirty..
Will PIX 515E 6.0 Version suppors the above and also confirm the suport compatibilty of ASA for the above technologies

Regards
ramu
0
Comment
Question by:RAMU CH
  • 3
  • 2
6 Comments
 
LVL 17

Expert Comment

by:Garry-G
Comment Utility
Both DMVPN (Dynamic Multipoint VPN) and GET VPN (Group Encrypted Transport) are not implemented in either PIX or ASA, it's only available on Cisco routers.

For devices supporting DMVPN, see this URL: http://www.cisco.com/en/US/partner/prod/collateral/iosswrel/ps6537/ps6586/ps6635/ps6658/data_sheet_c78-468520.html

For devices supporting GET, see this URL: http://www.cisco.com/en/US/partner/prod/collateral/iosswrel/ps6537/ps6586/ps6635/ps7180/product_data_sheet0900aecd80582067.html
0
 
LVL 18

Expert Comment

by:jmeggers
Comment Utility
DMVPN uses GRE tunnels, which is part of the reason it's not supported on the ASA (as Garry-G pointed out), as the ASA doesn't support GRE.  As the name implies, it sets up and encrypts tunnels dynamically as the need arises for one branch office to talk to another branch office.  Although traffic may still actually pass through the hub or corporate site, the burden of maintaining a whole bunch of individual tunnels, and separate routing entries for each, is reduced, as the tunnels are multipoint and use the same subnet.  Next-Hop Routing Protocol (NHRP) is needed to resolve where to go to get to the desired endpoint.

GET VPN does not use tunnels, and is designed to be used over private WAN networks such as a provider-based MPLS backbone.  Without the tunnels, it has somewhat lower overhead than DMVPN, and is arguably more scalable because of the use of group servers.  But, in general, it's a similar concept.

You will absolutely need to know these for CCIE-Sec.  Not just how to configure but how to troubleshoot as well.



0
 
LVL 1

Author Comment

by:RAMU CH
Comment Utility
Hi,

Thanks for your Info,I am not yet started fully on CCIE,i am above to..

Will you share the Experience of CCIE-Secuirty and help me  where i need  to focus to how to do LAB and written exam..

Pls provide the DMVPN and GET VPN troubleshooting Documnets
Regards
Ramu
0
IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

 
LVL 1

Author Comment

by:RAMU CH
Comment Utility
Hi,

What is the Difference betwwen IPSEC and GRE Tunnels,As i asked in the above , will you pls share the Troubleshoot DOCumnets of DMVPN and GETVPN

Regards
Ramu
0
 
LVL 17

Accepted Solution

by:
Garry-G earned 500 total points
Comment Utility
The two URLs I posted above should be a good start ... anyway, just out of curiosity - what's your current status as far as Cisco knowledge goes? It would appear to me that the knowledge required to get through some of the more "basic" courses like e.g. CCNA or CCNP already go a lot further than this and definitely than CCIE ...

As far as troubleshooting and design go:

DMVPN: http://www.cisco.com/en/US/products/ps6658/products_tech_note09186a0080b2a901.shtml

GET-VPN: http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6525/ps9370/ps7180/GETVPN_DIG_version_1_0_External.pdf (very detailed, 157 pages ...)
0
 
LVL 1

Author Closing Comment

by:RAMU CH
Comment Utility
Thanks
0

Featured Post

Free Trending Threat Insights Every Day

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

Have you experienced traffic destined through a Cisco ASA firewall disappears and you do not know if the traffic stops in the firewall or somewhere else? The solution is the capture feature. This feature was released in 6.2(1) and works in all firew…
Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…
In this seventh video of the Xpdf series, we discuss and demonstrate the PDFfonts utility, which lists all the fonts used in a PDF file. It does this via a command line interface, making it suitable for use in programs, scripts, batch files — any pl…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now