DMVPN & FlexVPN Advanced Scenarios
CCIE Enterprise Infrastructure EVE-NG / GNS3
مقصدObjectiveObjective
اس سبق کے بعد آپ DMVPN کے dual-hub اور spoke-to-spoke ڈیزائن بنا سکیں گے، اور FlexVPN کی بنیادی configuration سمجھ جائیں گے۔Is lesson ke baad aap DMVPN ke dual-hub aur spoke-to-spoke design bana sakenge, aur FlexVPN ki bunyadi configuration samajh jayenge.After this lesson you will be able to design DMVPN dual-hub and spoke-to-spoke, and understand basic FlexVPN configuration.
آسان مثالSimple AnalogySimple Analogy
DMVPN ایسا ہے جیسے ایک کمپنی کا ہیڈ آفس (hub) اور برانچز (spokes) — شروع میں سب ہیڈ آفس سے بات کرتے ہیں، پھر برانچز آپس میں براہ راست لائن بنا لیتی ہیں۔ FlexVPN اسی کا جدید، IKEv2 پر مبنی ورژن ہے۔DMVPN aisa hai jaise ek company ka head office (hub) aur branches (spokes) — shuru mein sab head office se baat karte hain, phir branches aapas mein direct line bana leti hain. FlexVPN isi ka modern, IKEv2 par based version hai.DMVPN is like a company HQ (hub) with branches (spokes) — initially everyone talks via HQ, then branches build direct tunnels to each other. FlexVPN is its modern IKEv2-based successor.
سیٹ اپLab SetupLab Setup
دو hubs (HUB1، HUB2) اور دو spokes (SPOKE1، SPOKE2) لیں۔ سب کے public IPs ہوں۔ پہلے single-hub DMVPN چلائیں، پھر dual-hub میں اپگریڈ کریں۔Do hubs (HUB1, HUB2) aur do spokes (SPOKE1, SPOKE2) lein. Sab ke public IPs hon. Pehle single-hub DMVPN chalayein, phir dual-hub mein upgrade karein.Use two hubs (HUB1, HUB2) and two spokes (SPOKE1, SPOKE2). All with public IPs. Build single-hub DMVPN first, then upgrade to dual-hub.
اقداماتStepsSteps
Step 1
HUB1 پر tunnel انٹرفیس بنائیں: mGRE mode، NHRP network-id، اور tunnel key۔ Hub NHRP server (NHS) کا کردار ادا کرتا ہے۔HUB1 par tunnel interface banayein: mGRE mode, NHRP network-id, aur tunnel key. Hub NHRP server (NHS) ka kirdar ada karta hai.Create the tunnel interface on HUB1: mGRE mode, NHRP network-id, tunnel key. The hub acts as the NHRP server (NHS).
interface Tunnel0 ip address 10.0.0.1 255.255.255.0 tunnel source GigabitEthernet0/0 tunnel mode gre multipoint ip nhrp network-id 100 ip nhrp map multicast dynamic
Step 2
Spoke پر tunnel بنائیں اور hub کو NHS کے طور پر map کریں۔ Spoke اپنے public IP کو NHRP کے ذریعے hub پر register کرتا ہے۔Spoke par tunnel banayein aur hub ko NHS ke tor par map karein. Spoke apne public IP ko NHRP ke zariye hub par register karta hai.Build the spoke tunnel and map the hub as NHS. The spoke registers its public IP with the hub via NHRP.
interface Tunnel0 ip address 10.0.0.11 255.255.255.0 tunnel source GigabitEthernet0/0 tunnel mode gre multipoint ip nhrp network-id 100 ip nhrp nhs 10.0.0.1 nbma 203.0.113.1 multicast
Step 3
IPsec تحفظ شامل کریں: transform-set اور crypto profile بنا کر tunnel پر لگائیں۔ اب تمام DMVPN ٹریفک encrypted ہے۔IPsec protection shamil karein: transform-set aur crypto profile bana kar tunnel par lagayein. Ab tamam DMVPN traffic encrypted hai.Add IPsec protection: create a transform-set and crypto profile, apply to the tunnel. All DMVPN traffic is now encrypted.
crypto ipsec transform-set DMVPN-TS esp-aes esp-sha-hmac crypto ipsec profile DMVPN-PROF set transform-set DMVPN-TS interface Tunnel0 tunnel protection ipsec profile DMVPN-PROF
Step 4
Spoke-to-spoke ٹنلز کے لیے hub پر NHRP redirect اور spoke پر shortcut فعال کریں۔ پھر ایک spoke سے دوسرے کو ping کریں اور 'show dmvpn' میں dynamic tunnel دیکھیں۔Spoke-to-spoke tunnels ke liye hub par NHRP redirect aur spoke par shortcut active karein. Phir ek spoke se doosre ko ping karein aur 'show dmvpn' mein dynamic tunnel dekhen.For spoke-to-spoke tunnels enable NHRP redirect on the hub and shortcut on spokes. Ping spoke-to-spoke and watch the dynamic tunnel in show dmvpn.
interface Tunnel0 ip nhrp redirect ip nhrp shortcut show dmvpn
Step 5
Dual-hub بنائیں: HUB2 پر بھی یہی config (الگ tunnel IP کے ساتھ) اور spokes پر دوسرا NHS map کریں۔ ایک hub بند کر کے failover ٹیسٹ کریں۔Dual-hub banayein: HUB2 par bhi yehi config (alag tunnel IP ke saath) aur spokes par doosra NHS map karein. Ek hub band kar ke failover test karein.Build dual-hub: same config on HUB2 (different tunnel IP), second NHS mapped on spokes. Shut one hub and test failover.
ip nhrp nhs 10.0.0.2 nbma 203.0.113.2 multicast show ip nhrp
Step 6
FlexVPN کی بنیاد: IKEv2 keyring، profile، اور authorization policy۔ FlexVPN ایک ہی framework میں site-to-site اور remote-access دونوں دیتا ہے۔FlexVPN ki bunyaad: IKEv2 keyring, profile, aur authorization policy. FlexVPN ek hi framework mein site-to-site aur remote-access dono deta hai.FlexVPN basics: IKEv2 keyring, profile, and authorization policy. FlexVPN gives site-to-site and remote-access in one framework.
crypto ikev2 keyring FLEX-KR peer SPOKE address 0.0.0.0 0.0.0.0 pre-shared-key cisco123 crypto ikev2 profile FLEX-PROF match identity remote address 0.0.0.0 authentication remote pre-share authentication local pre-share keyring local FLEX-KR
Step 7
FlexVPN کو tunnel انٹرفیس سے جوڑیں اور verify کریں۔ یاد رکھیں: FlexVPN config DMVPN سے زیادہ ماڈیولر ہے — ہر حصہ الگ policy میں۔FlexVPN ko tunnel interface se jorein aur verify karein. Yaad rakhen: FlexVPN config DMVPN se zyada modular hai — har hissa alag policy mein.Attach FlexVPN to the tunnel interface and verify. Remember: FlexVPN config is more modular than DMVPN — each piece lives in its own policy.
interface Tunnel1 tunnel protection ipsec profile FLEX-PROF show crypto ikev2 sa
تصدیقVerifyVerify
یقین کریں کہ NHRP registrations دونوں hubs پر ہیں، spoke-to-spoke dynamic tunnels بن رہے ہیں، IPsec SAs up ہیں، اور ایک hub کی failure پر ٹریفک دوسرے پر جاتا ہے۔Yaqeen karein ke NHRP registrations dono hubs par hain, spoke-to-spoke dynamic tunnels ban rahe hain, IPsec SAs up hain, aur ek hub ki failure par traffic doosre par jata hai.Confirm NHRP registrations exist on both hubs, spoke-to-spoke dynamic tunnels form, IPsec SAs are up, and traffic fails over when one hub dies.
show dmvpn show ip nhrp show crypto ipsec sa show crypto ikev2 sa
خرابی دور کرناTroubleshootingTroubleshooting
⚠️ NHRP registration نہیں ہو رہی — 'show ip nhrp' خالی ہے۔NHRP registration nahi ho rahi — 'show ip nhrp' khaali hai.NHRP registration failing — show ip nhrp is empty.
✅ NHS mapping چیک کریں (NBMA address درست؟)، tunnel key اور network-id دونوں طرف match کریں، اور IPsec profile mismatch دیکھیں۔NHS mapping check karein (NBMA address durust?), tunnel key aur network-id dono taraf match karein, aur IPsec profile mismatch dekhen.Check NHS mapping (correct NBMA address?), match tunnel key and network-id on both sides, and look for IPsec profile mismatch.
⚠️ Spoke-to-spoke tunnel نہیں بن رہا، ٹریفک hub سے گزر رہا ہے۔Spoke-to-spoke tunnel nahi ban raha, traffic hub se guzar raha hai.Spoke-to-spoke tunnel not forming; traffic goes via hub.
✅ Hub پر 'ip nhrp redirect' اور spoke پر 'ip nhrp shortcut' لگا ہونا ضروری ہے۔ Routing protocol کو spoke prefixes advertise کرنے چاہئیں۔Hub par 'ip nhrp redirect' aur spoke par 'ip nhrp shortcut' laga hona zaroori hai. Routing protocol ko spoke prefixes advertise karne chahiyein.You need 'ip nhrp redirect' on the hub and 'ip nhrp shortcut' on spokes. The routing protocol must advertise spoke prefixes.
انٹرویو سوالاتInterview Q&AInterview Q&A
❓ DMVPN Phase 2 اور Phase 3 میں کیا فرق ہے؟DMVPN Phase 2 aur Phase 3 mein kya farq hai?What is the difference between DMVPN Phase 2 and Phase 3?
Phase 2 میں spokes براہ راست tunnel بناتے ہیں لیکن hub کے ذریعے routing ہوتی ہے۔ Phase 3 میں NHRP redirect/shortcut سے spoke کو hub کے بغیر بہترین next-hop ملتا ہے — زیادہ scalable۔Phase 2 mein spokes direct tunnel banate hain lekin hub ke zariye routing hoti hai. Phase 3 mein NHRP redirect/shortcut se spoke ko hub ke baghair behtareen next-hop milta hai — zyada scalable.In Phase 2 spokes build direct tunnels but routing still goes via the hub. Phase 3 uses NHRP redirect/shortcut so spokes get the optimal next-hop without the hub — more scalable.
❓ FlexVPN، DMVPN سے کیوں بہتر سمجھا جاتا ہے؟FlexVPN, DMVPN se kyun behtar samjha jata hai?Why is FlexVPN considered better than DMVPN?
IKEv2 پر مبنی ہے (تیز، محفوظ)، ایک ہی framework site-to-site اور remote-access دونوں کے لیے، اور ماڈیولر policies سے config صاف رہتی ہے۔IKEv2 par based hai (tez, mehfooz), ek hi framework site-to-site aur remote-access dono ke liye, aur modular policies se config saaf rehti hai.It's IKEv2-based (faster, more secure), one framework covers site-to-site and remote-access, and modular policies keep configs clean.