Solved

DMVPN and GET VPNconcept

Posted on 2011-09-12
6
743 Views
Last Modified: 2012-05-12
Hi,
What is DM VPN and GET VPN  and how to configure. Will you provide a best sample scenario to do this. because i am preparing for CCIE Secuirty..
Will PIX 515E 6.0 Version suppors the above and also confirm the suport compatibilty of ASA for the above technologies

Regards
ramu
0
Comment
Question by:RAMU CH
  • 3
  • 2
6 Comments
 
LVL 17

Expert Comment

by:Garry-G
ID: 36522890
Both DMVPN (Dynamic Multipoint VPN) and GET VPN (Group Encrypted Transport) are not implemented in either PIX or ASA, it's only available on Cisco routers.

For devices supporting DMVPN, see this URL: http://www.cisco.com/en/US/partner/prod/collateral/iosswrel/ps6537/ps6586/ps6635/ps6658/data_sheet_c78-468520.html

For devices supporting GET, see this URL: http://www.cisco.com/en/US/partner/prod/collateral/iosswrel/ps6537/ps6586/ps6635/ps7180/product_data_sheet0900aecd80582067.html
0
 
LVL 18

Expert Comment

by:jmeggers
ID: 36524803
DMVPN uses GRE tunnels, which is part of the reason it's not supported on the ASA (as Garry-G pointed out), as the ASA doesn't support GRE.  As the name implies, it sets up and encrypts tunnels dynamically as the need arises for one branch office to talk to another branch office.  Although traffic may still actually pass through the hub or corporate site, the burden of maintaining a whole bunch of individual tunnels, and separate routing entries for each, is reduced, as the tunnels are multipoint and use the same subnet.  Next-Hop Routing Protocol (NHRP) is needed to resolve where to go to get to the desired endpoint.

GET VPN does not use tunnels, and is designed to be used over private WAN networks such as a provider-based MPLS backbone.  Without the tunnels, it has somewhat lower overhead than DMVPN, and is arguably more scalable because of the use of group servers.  But, in general, it's a similar concept.

You will absolutely need to know these for CCIE-Sec.  Not just how to configure but how to troubleshoot as well.



0
 
LVL 1

Author Comment

by:RAMU CH
ID: 36527130
Hi,

Thanks for your Info,I am not yet started fully on CCIE,i am above to..

Will you share the Experience of CCIE-Secuirty and help me  where i need  to focus to how to do LAB and written exam..

Pls provide the DMVPN and GET VPN troubleshooting Documnets
Regards
Ramu
0
Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

 
LVL 1

Author Comment

by:RAMU CH
ID: 36527193
Hi,

What is the Difference betwwen IPSEC and GRE Tunnels,As i asked in the above , will you pls share the Troubleshoot DOCumnets of DMVPN and GETVPN

Regards
Ramu
0
 
LVL 17

Accepted Solution

by:
Garry-G earned 500 total points
ID: 36527437
The two URLs I posted above should be a good start ... anyway, just out of curiosity - what's your current status as far as Cisco knowledge goes? It would appear to me that the knowledge required to get through some of the more "basic" courses like e.g. CCNA or CCNP already go a lot further than this and definitely than CCIE ...

As far as troubleshooting and design go:

DMVPN: http://www.cisco.com/en/US/products/ps6658/products_tech_note09186a0080b2a901.shtml

GET-VPN: http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6525/ps9370/ps7180/GETVPN_DIG_version_1_0_External.pdf (very detailed, 157 pages ...)
0
 
LVL 1

Author Closing Comment

by:RAMU CH
ID: 36715474
Thanks
0

Featured Post

Gigs: Get Your Project Delivered by an Expert

Select from freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely and get projects done right.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Multicast on 3750x cisco router 1 37
2960 and a VLAN id of 1237 2 60
Cisco RV 130 - No internet on wired connections, wireless clients ok 32 60
ASA and ICMP 4 20
Overview The Cisco PIX 501, PIX 506e, ASA 5505 and ASA 5510 (most if not all of this information will be relevant to the PIX 515e but I do not have a working configuration handy to verify the validity) are primarily used within small to medium busi…
For months I had no idea how to 'discover' the IP address of the other end of a link (without asking someone who knows), and it drove me batty. Think about it. You can't use Cisco Discovery Protocol (CDP) because it's not implemented on the ASAs.…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

776 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question