Lab Introduction This lab is still about DMVPN Phase 3 point-to-multipoint OSPF. It focuses on IKEv1 instead of IKEv2 in previous post. Later part of
This lab is still about DMVPN Phase 3 point-to-multipoint OSPF. It focuses on IKEv1 instead of IKEv2 in previous post. Later part of the lab will also introduce NHS cluster for dual-head in single DMVPN design.
The topology is as below:
VRF-aware DMVPN with IKEv1
‘VRF-aware ipsec cheat sheet’ is an excellent reference provides the following key points on configuring VRF-aware DMVPN with IKEv1:
- “ip vrf forwarding <ivrf>” on the tunnel interface
- “tunnel vrf <fvrf>” on the tunnel interface
- crypto keyring tagged with fvrf
- NO “vrf <ivrf>” on isakmp profile
- fvrf on match statement of isakmp profile
- no need to worry about RRI (tunnel destination needs to be reachable in fvrf), inside traffic gets routed to the tunnel interface
- interfaces in their VRF and proper routes in each VRF as well
My lab configuration example is as below:
Please refer to Cisco reference: ‘DMVPN-Tunnel Health Monitoring and Recovery Backup NHS’ for articulation on NHS cluster.
My lab example is as below: