A few weeks back, Gartner analyst Bjarne Munch stated, “Internet and MPLS play an equally important role for enterprise connectivity. Network planners must establish a unified WAN with strong integration between these two networks to avoid performance problems.”[i]
So, why should IT move to a hybrid WAN architecture? What are the benefits?
#1 – Control Costs
Growth in bandwidth demand is overwhelming customer networks, particularly at the branch. IP traffic is expected to grow three times over the next five years due to video, cloud applications, rich media and data center centralization. At the same time, Nemertes’ 2014 WAN Best Practices and Success Factors report states that 60% of IT WAN budgets will remain flat or decline in 2015. Read More »
Tags: Akamai Connect, AVC, DMVPN, Glue, hybrid WAN, Intelligent WAN, IWAN, LiveAction, PfRv3
Since DMVPN has been added to the CCIE v5 BluePrint (http://www.cisco.com/web/learning/exams/docs/ccieRS_Lab5.pdf) I figured that now was just as good of a time as any to write this blog.
DMVPN stands for Dynamic Multipoint VPN and it is an effective solution for dynamic secure overlay networks.
DMVPN is combination of the following technologies:
- Multipoint GRE (mGRE)
- Next-Hop Resolution Protocol (NHRP)
- Dynamic Routing Protocol (EIGRP, RIP, OSPF, BGP)
- Dynamic IPsec encryption
- Cisco Express Forwarding (CEF)
Topology that we will be starting with:
First thing will be to complete the base configurations on R1, R2 & R3. This will consist of configuring the IP addresses on the above interfaces and setting up the routing protocol to distribute the routes. In this case we will use EIGRP 123. Read More »
Tags: #ciscochampion, BGP, CCIE, DMVPN, EIGRP, OSPF
In my last blog I talked about the value of Pfr to the IWAN solution. This week I wanted to talk about DMVPN and why it is going to be a critical component of your IWAN deployment.
Your IWAN topology will most likely consist of one or more internet connections which means that your data will be traveling over untrusted connections and shared environments so security is going to be top of mind. So how do you secure your data over the internet and other untrusted or shared environments? Well DMVPN (Dynamic Multi-point Virtual Private Network) is based on VPN the same technology that many of you use today to securely connect back to your office when you are traveling or working from home. A VPN will create a tunnel between two end-points and then encrypt all data traveling over the tunnel. VPN’s can connect users to a remote site, client-to-site VPN, or connect two remote sites, site-to-site VPN. Unlike VPN, DMVPN can securely connect multiple points together dynamically.
So how does DMVPN work and what is the benefit to IWAN? DMVPN works on top of your WAN infrastructure which means that DMVPN tunnels will be established between branch sites as traffic flow demands. In a common hub and spoke topology example, when data needs to be sent from the spoke to the hub site, the spoke will establish a VPN tunnel to the hub by registering first with the hub. In order for each tunnel to function a new dynamic IP address is created at the branch since the hub site will initiate the connection. In order for data to be routed between sites over the DMVPN tunnels, routing information will need to be exchanged. As more tunnels are created there will be more dynamically created IP addresses and traditional routing protocols like BGP or EIGRP are used to efficiently share routing information so all sites can talk to each other. Lastly QoS is applied to each tunnel to ensure that the hub site does not oversubscribe the spoke sites.
Read More »
Tags: Cisco ISR, DMVPN, IWAN, PfR
Imagine that you have several branch offices that are using WAN demanding applications like Salesforce.com, Office 365, Virtual Desktops, Video Teleconferencing and more. You are using those expensive MPLS/VPN WAN connections as you don’t want to risk it and probably because when you started to work there it was already there and … why mess around with something that is working, right? Normally I would agree with that but when IT budgets are shrinking and the network needs to step up and support those business critical apps, there is no other way but to innovate.
At any given time your network carries information from LAN to WAN and vice versa, some is important and some is less important. In many cases as a network admin you don’t have the visibility to distinguish between them, so what do you do when those critical apps are starting to act up? Usually the answer will be to buy more WAN bandwidth and that will give the apps and the user experience behind them some breathing space. But all you’re doing is buying time. Buying time never solves the problem because you will need to treat the symptoms again in a few weeks or months.
However, you can solve the problem and not just treat the symptoms using Cisco Intelligent WAN or IWAN for short.
Read More »
Tags: AVC, Cisco Router, DMVPN, Intelligent WAN, ISR-AX, IWAN, PfR, QoS, waas, WAN Optimization