<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: DMVPN Explained</title>
	<atom:link href="http://blog.ine.com/2008/08/02/dmvpn-explained/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.ine.com/2008/08/02/dmvpn-explained/</link>
	<description>Helping you become a Cisco Certified Internetwork Expert</description>
	<lastBuildDate>Wed, 10 Mar 2010 16:27:50 -0800</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Zen</title>
		<link>http://blog.ine.com/2008/08/02/dmvpn-explained/comment-page-1/#comment-95317</link>
		<dc:creator>Zen</dc:creator>
		<pubDate>Mon, 22 Feb 2010 11:01:43 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ine.com/?p=214#comment-95317</guid>
		<description>About my above post, i think it could help someone on the same foot.

After implementing the following command I havent noticed anymore weird nhrp registers, and also we changed the address which crypto should allow to make a request for registers.

crypto isakmp aggressive-mode disable
crypto isakmp key 0 CISCO address [b]ActualIPAdress[/b]</description>
		<content:encoded><![CDATA[<p>About my above post, i think it could help someone on the same foot.</p>
<p>After implementing the following command I havent noticed anymore weird nhrp registers, and also we changed the address which crypto should allow to make a request for registers.</p>
<p>crypto isakmp aggressive-mode disable<br />
crypto isakmp key 0 CISCO address [b]ActualIPAdress[/b]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ali</title>
		<link>http://blog.ine.com/2008/08/02/dmvpn-explained/comment-page-1/#comment-89881</link>
		<dc:creator>Ali</dc:creator>
		<pubDate>Wed, 20 Jan 2010 10:44:33 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ine.com/?p=214#comment-89881</guid>
		<description>Can I implement a Laptop installed with Cisco VPN client as a DMVPN Spoke Site, LIke for eg. I have an employee working from a remote location and has internet connectivity and needs to access other spokes too , directly without the traffic being sent from the laptop to the hub and then to the other remote site, instead a dynamic tunnel needs to be created from the Laptop to the other spoke?

Is it possible to implement DMVPN/NHRP on a Cisco VPN client?</description>
		<content:encoded><![CDATA[<p>Can I implement a Laptop installed with Cisco VPN client as a DMVPN Spoke Site, LIke for eg. I have an employee working from a remote location and has internet connectivity and needs to access other spokes too , directly without the traffic being sent from the laptop to the hub and then to the other remote site, instead a dynamic tunnel needs to be created from the Laptop to the other spoke?</p>
<p>Is it possible to implement DMVPN/NHRP on a Cisco VPN client?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zen</title>
		<link>http://blog.ine.com/2008/08/02/dmvpn-explained/comment-page-1/#comment-86795</link>
		<dc:creator>Zen</dc:creator>
		<pubDate>Mon, 28 Dec 2009 14:08:19 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ine.com/?p=214#comment-86795</guid>
		<description>Hello,

I implemented DMVPN a while ago, and used to work great.
Recently I noticed memory &amp; cpu usages going very high, and when I checked with show processes cpu , I saw that NHRP was using 40-60% of the CPU constantly.

I ran show ip nhrp , and the results really frightened me, there are lots of unknown ip address in there , same is happening on my Hub and on Spokes.

Here&#039;s one of the many entries:

97.100.x.x/32 via 192.168.x.1
   Tunnel0 created 00:00:03, expire 00:05:58
   Type: dynamic, Flags: router

There are many other different IP addresses that look like the one above, any idea whats going on?</description>
		<content:encoded><![CDATA[<p>Hello,</p>
<p>I implemented DMVPN a while ago, and used to work great.<br />
Recently I noticed memory &amp; cpu usages going very high, and when I checked with show processes cpu , I saw that NHRP was using 40-60% of the CPU constantly.</p>
<p>I ran show ip nhrp , and the results really frightened me, there are lots of unknown ip address in there , same is happening on my Hub and on Spokes.</p>
<p>Here&#8217;s one of the many entries:</p>
<p>97.100.x.x/32 via 192.168.x.1<br />
   Tunnel0 created 00:00:03, expire 00:05:58<br />
   Type: dynamic, Flags: router</p>
<p>There are many other different IP addresses that look like the one above, any idea whats going on?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sinisa</title>
		<link>http://blog.ine.com/2008/08/02/dmvpn-explained/comment-page-1/#comment-83981</link>
		<dc:creator>Sinisa</dc:creator>
		<pubDate>Wed, 09 Dec 2009 11:03:22 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ine.com/?p=214#comment-83981</guid>
		<description>@Naru

You can use ip sla traps and snmp.</description>
		<content:encoded><![CDATA[<p>@Naru</p>
<p>You can use ip sla traps and snmp.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Naru</title>
		<link>http://blog.ine.com/2008/08/02/dmvpn-explained/comment-page-1/#comment-73893</link>
		<dc:creator>Naru</dc:creator>
		<pubDate>Thu, 22 Oct 2009 12:48:19 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ine.com/?p=214#comment-73893</guid>
		<description>I am currently using Orion SolarWinds NPM to monitor my nodes, though I needed to monitor the tunnels when they go up &amp; down so I can send the report to my ISP, but I saw that even if the tunnel is not connected, it still shows as UP - UP, is there a way to change this behavior? For example, when you can&#039;t reach that tunnel, the tunnel should go like UP - DOWN , or if there&#039;s any other method to monitor those tunnels would be great.

Thanks</description>
		<content:encoded><![CDATA[<p>I am currently using Orion SolarWinds NPM to monitor my nodes, though I needed to monitor the tunnels when they go up &amp; down so I can send the report to my ISP, but I saw that even if the tunnel is not connected, it still shows as UP &#8211; UP, is there a way to change this behavior? For example, when you can&#8217;t reach that tunnel, the tunnel should go like UP &#8211; DOWN , or if there&#8217;s any other method to monitor those tunnels would be great.</p>
<p>Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sinisa</title>
		<link>http://blog.ine.com/2008/08/02/dmvpn-explained/comment-page-1/#comment-66960</link>
		<dc:creator>Sinisa</dc:creator>
		<pubDate>Tue, 22 Sep 2009 23:05:40 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ine.com/?p=214#comment-66960</guid>
		<description>This is a grat explanation of DMVPN, the best one I could find on the Internet.

Question: I have DMVPN topology with two redundant NHSs (pointing each other) and several NHCs, and that topology works fine. Problem is when I shut NHS#1 (or it crashes) and bring it back, and then the same with NHS#2, my NHCs can&#039;t see each other any more. They even can&#039;t see NHSs, and NHSs can see only each other. I can only solve it by shut/no shut tunnel interfaces on NHCs.
Is there a rule or a behaviour of NHRP that NHSs have to be configured first in network, then NHCs?

I run multi area OSPF over multiple GRE tunnels, and it&#039;s all protected with IPSec. I have removed IPSec protection and OSPF in observed mGRE tunnel to have a clear situation.

Any help?</description>
		<content:encoded><![CDATA[<p>This is a grat explanation of DMVPN, the best one I could find on the Internet.</p>
<p>Question: I have DMVPN topology with two redundant NHSs (pointing each other) and several NHCs, and that topology works fine. Problem is when I shut NHS#1 (or it crashes) and bring it back, and then the same with NHS#2, my NHCs can&#8217;t see each other any more. They even can&#8217;t see NHSs, and NHSs can see only each other. I can only solve it by shut/no shut tunnel interfaces on NHCs.<br />
Is there a rule or a behaviour of NHRP that NHSs have to be configured first in network, then NHCs?</p>
<p>I run multi area OSPF over multiple GRE tunnels, and it&#8217;s all protected with IPSec. I have removed IPSec protection and OSPF in observed mGRE tunnel to have a clear situation.</p>
<p>Any help?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Naru</title>
		<link>http://blog.ine.com/2008/08/02/dmvpn-explained/comment-page-1/#comment-65668</link>
		<dc:creator>Naru</dc:creator>
		<pubDate>Mon, 14 Sep 2009 14:50:41 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ine.com/?p=214#comment-65668</guid>
		<description>Very nice explanation, keep the good work up! ;)</description>
		<content:encoded><![CDATA[<p>Very nice explanation, keep the good work up! <img src='http://blog.ine.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Petr Lapukhov, CCIE #16379</title>
		<link>http://blog.ine.com/2008/08/02/dmvpn-explained/comment-page-1/#comment-58834</link>
		<dc:creator>Petr Lapukhov, CCIE #16379</dc:creator>
		<pubDate>Wed, 05 Aug 2009 04:13:43 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ine.com/?p=214#comment-58834</guid>
		<description>1) You need to use PIM-NBMA mode on the hub tunnel interface to allow for neighbor tracking and splitting the NBMA interface into a group of P2P links. This of course only works with PIM sparse.
2) With Phase 2, you need to configure every spoke with two NHS addresses and configure both NHSes to point to each other. This will ensure proper NHS cache syncrhonization.
2) With Phase 3, everythin should be working automatically, even if you have multiple spokes registering to different hubs, the chain of redirects is based on the routing topology, not the NHS connections.</description>
		<content:encoded><![CDATA[<p>1) You need to use PIM-NBMA mode on the hub tunnel interface to allow for neighbor tracking and splitting the NBMA interface into a group of P2P links. This of course only works with PIM sparse.<br />
2) With Phase 2, you need to configure every spoke with two NHS addresses and configure both NHSes to point to each other. This will ensure proper NHS cache syncrhonization.<br />
2) With Phase 3, everythin should be working automatically, even if you have multiple spokes registering to different hubs, the chain of redirects is based on the routing topology, not the NHS connections.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ob</title>
		<link>http://blog.ine.com/2008/08/02/dmvpn-explained/comment-page-1/#comment-58515</link>
		<dc:creator>ob</dc:creator>
		<pubDate>Sat, 01 Aug 2009 16:27:44 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ine.com/?p=214#comment-58515</guid>
		<description>Great article!

I have two questions though:

1) How do I get spoke-to-spoke multicasting to work. Even the simple &quot;ping 224.0.0.1&quot; on spokeA will not get a reply from spokeB, only the HUB.

2) How do I set up redundant NHS?</description>
		<content:encoded><![CDATA[<p>Great article!</p>
<p>I have two questions though:</p>
<p>1) How do I get spoke-to-spoke multicasting to work. Even the simple &#8220;ping 224.0.0.1&#8243; on spokeA will not get a reply from spokeB, only the HUB.</p>
<p>2) How do I set up redundant NHS?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Security &#171; CCIE Study Notes</title>
		<link>http://blog.ine.com/2008/08/02/dmvpn-explained/comment-page-1/#comment-47137</link>
		<dc:creator>Security &#171; CCIE Study Notes</dc:creator>
		<pubDate>Tue, 12 May 2009 09:03:37 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ine.com/?p=214#comment-47137</guid>
		<description>[...] explained here but i&#8217;m out of steam for security today    Comments [...]</description>
		<content:encoded><![CDATA[<p>[...] explained here but i&#8217;m out of steam for security today    Comments [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
