Solved

DMVPN mGRE vs IPSec VPN

Posted on 2014-07-30
4
789 Views
Last Modified: 2014-08-20
Hello Experts,

I'm looking for help compiling convincing arguments why my company should migrate from their existing IPSec VPN to Ciscos DMVPN.

Just so you know I fully understand why DMVPN is a better option if you were creating an IP VPN from scratch. However, I'm trying to convince the organisation to tear down existing and rebuild their IP VPN with Cisco's DMVPN.

I'm very interested to hear what experts come back with on this topic

cpatte7372
0
Comment
Question by:cpatte7372
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 20

Expert Comment

by:rauenpc
ID: 40229241
Some of my arguments would depend on existing configuration.
Are you running GRE over IPSEC in any way?
Are you using static routes to get traffic to go through the tunnels? Are these routes being redistributed into routing protocols?
Do you have multiple head ends or redundant tunnels?
Any need or desire for spoke to spoke traffic?
What hardware is used for the tunnels today? ASA's, routers, etc.
Any expected site growth or additions?
How often are changes made, such as adding/removing subnets at the hubs or spokes?
0
 

Author Comment

by:cpatte7372
ID: 40229376
We are running GRE over IPSEC in tunnel mode
We use static routes which are being redistributed into eigrp
We have multiple headends.
Spoke to spoke allows for a fully meshed environment.
We use 887 for the tunnels.
There is a mild expectation in growth,


So, what do you experts think?
0
 
LVL 22

Accepted Solution

by:
Matt V earned 500 total points
ID: 40268517
Switching to the DMVPN model with what you describe would:
- lessen the amount of configuration on the hub router(s)
- make adding a new spoke easier/quicker
- allow dynamic tunnels between spokes only when traffic requires it
- would allow fully dynamic routing with no static route maintenance
- would allow for spoke sites with dynamic IPs (slightly less secure) if required
- should work find with 887 routers, less work for the routers with DMVPN versus specified tunnels
0
 

Author Closing Comment

by:cpatte7372
ID: 40272367
Cheers
0

Featured Post

Raise the IQ of Your IT Alerts

From IT major incidents to manufacturing line slowdowns, every business process generates insights that need to reach the people required to take action. You need a platform that integrates with your business tools to create fully enabled DevOps toolchains.

You need xMatters.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The Cisco RV042 router is a popular small network interfacing device that is often used as an internet gateway. Network administrators need to get at the management interface to make settings, change passwords, etc. This access is generally done usi…
There are two basic ways to configure a static route for Cisco IOS devices. I've written this article to highlight a case study comparing the configuration of a static route using the next-hop IP and the configuration of a static route using an outg…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses

690 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question