View Cart
0 Items | Total: US$0.00
Welcome,      Register

You are here

SEC0001 - DMVPN Phase 1 and 2

Average: 5 (1 vote)
Difficulty Level: 
Lab Document: 
<Please login to see the content>

The video extends our previous knowledge on NHRP (see videos RS0015, RS0016) by adding IPSec and form DMVPN. We walk through the crypto configuration and point out the specific to support dynamic IPSec tunnel creation for spoke-to-spoke communication. DMVPN is one of the most popular forms of WAN connectivity over internet due to the low configuration requirement and ability to allow additional sites to be brought up with minimal effort, without modifying the Hub configuration.

Topic includes
  • DMVPN Phase 1 and 2
  • IPSec configuration with 'tunnel protection
  • Use tunnel mode transport if IPSec terminates on the same device as GRE and save 20 bytes of an IP header per packet.
  • Tunnel mode on Hub and Spoke routers do not need to match. If only Hub-and-Spoke is required, Spoke can operate on point-to-point mode (default) instead of multipoint.

About Author

Metha Cheiwanichakorn, CCIE#23585 (RS, Sec, SP), is a Cisco networking enthusiast with years of experience in the industry. He is currently working as a consulting engineer for a Cisco partner. As a founder of and an instructor at, Metha enjoys learning and challenges himself with new Cisco technologies.