Showing posts with label DMVPN. Show all posts
Showing posts with label DMVPN. Show all posts

CCIE Security Lab: Dual-Hub DMVPN

Now that OSPF is all fixed I can set up the Dual-Hub DMVPN. I need to decide on an addressing scheme to go across the DMVPN network, and I think that 192.168.1.0/24 is suitable; it's far enough away from the main networks 10.1.x.0/24 subnets to be easily distinguishable.


There are a couple of things to remember here. Firstly, we need to open up the transparent ASA to permit the DMVPN traffic, and similarly on the failover ASAs. The DMVPN hubs also need to be NAT-aware, as we will connect the clients to the NAT address (10.1.16.200 and 10.1.26.200), rather than the loopbacks. Thankfully, they handle this part themselves, but we do need to factor this in (as you'll see later).

We will start off by creating the isakmp policy and transport-sets that we will use. Because it is identical we can create it on notepad, nd then paste onto the routers, or create it on one router and then do "sh run | s crypto" and then copy and paste:
DMVPN-Hub1(config)#crypto isakmp policy 10
DMVPN-Hub1(config-isakmp)#encryption 3des
DMVPN-Hub1(config-isakmp)#authentication pre-share
DMVPN-Hub1(config-isakmp)#group 2
DMVPN-Hub1(config-isakmp)#exit
DMVPN-Hub1(config)#crypto ipsec transform-set esp-3des-sha-hmac esp-3des esp-sha-hmac 
DMVPN-Hub1(cfg-crypto-trans)#mode transport
DMVPN-Hub1(cfg-crypto-trans)#exit
DMVPN-Hub1(config)#crypto ipsec profile DMVPN
DMVPN-Hub1(ipsec-profile)#set transform-set esp-3des-sha-hmac
DMVPN-Hub1(ipsec-profile)#exit
DMVPN-Hub1(config)#crypto isakmp key cisco address 0.0.0.0 0.0.0.0
This then gets copied to the other routers:
DMVPN-Hub2(config)#crypto isakmp policy 10
DMVPN-Hub2(config-isakmp)# encr 3des
DMVPN-Hub2(config-isakmp)# authentication pre-share
DMVPN-Hub2(config-isakmp)# group 2
DMVPN-Hub2(config-isakmp)# exit
DMVPN-Hub2(config)#crypto ipsec transform-set esp-3des-sha-hmac esp-3des esp-sha-hmac     
DMVPN-Hub2(cfg-crypto-trans)# mode transport
DMVPN-Hub2(cfg-crypto-trans)#crypto ipsec profile DMVPN
DMVPN-Hub2(ipsec-profile)# set transform-set esp-3des-sha-hmac 
DMVPN-Hub2(ipsec-profile)# exit
DMVPN-Hub2(config)#crypto isakmp key cisco address 0.0.0.0 0.0.0.0

DMVPN-Client(config)#crypto isakmp policy 10
DMVPN-Client(config-isakmp)# encr 3des
DMVPN-Client(config-isakmp)# authentication pre-share
DMVPN-Client(config-isakmp)# group 2
DMVPN-Client(config-isakmp)# exit
DMVPN-Client(config)#crypto ipsec transform-set esp-3des-sha-hmac esp-3des esp-sha-hmac   
DMVPN-Client(cfg-crypto-trans)# mode transport
DMVPN-Client(cfg-crypto-trans)#crypto ipsec profile DMVPN
DMVPN-Client(ipsec-profile)# set transform-set esp-3des-sha-hmac 
DMVPN-Client(ipsec-profile)# exit
DMVPN-Client(config)#crypto isakmp key cisco address 0.0.0.0 0.0.0.0

EzVPN-Server(config)#crypto isakmp policy 10
EzVPN-Server(config-isakmp)# encr 3des
EzVPN-Server(config-isakmp)# authentication pre-share
EzVPN-Server(config-isakmp)# group 2
EzVPN-Server(config-isakmp)# exit
EzVPN-Server(config)#crypto ipsec transform-set esp-3des-sha-hmac esp-3des esp-sha-hmac   
EzVPN-Server(cfg-crypto-trans)# mode transport
EzVPN-Server(cfg-crypto-trans)#crypto ipsec profile DMVPN
EzVPN-Server(ipsec-profile)# set transform-set esp-3des-sha-hmac 
EzVPN-Server(ipsec-profile)# exit
EzVPN-Server(config)#crypto isakmp key cisco address 0.0.0.0 0.0.0.0
The beauty of things like DMVPN is that it's one of those technologies with little variation in the commands, so we can do a lot of direct cutting and pasting.

Now we can start creating the tunnels, and it's easier to break out Notepad, and chuck in the basics:
int tunnel 0
tun mode gre multipoint
bandwidth 1000
delay 1000
no ip redirects
ip mtu 1360
ip nhrp shortcut
tunnel key 101
tunnel protection ipsec profile DMVPN
Let's paste this onto the routers:
DMVPN-Hub1(config-if)#int tunnel 0
DMVPN-Hub1(config-if)#tun mode gre multipoint
DMVPN-Hub1(config-if)#bandwidth 1000
DMVPN-Hub1(config-if)#delay 1000
DMVPN-Hub1(config-if)#no ip redirects
DMVPN-Hub1(config-if)#ip mtu 1360
DMVPN-Hub1(config-if)#ip nhrp shortcut
DMVPN-Hub1(config-if)#tunnel key 101
DMVPN-Hub1(config-if)#tunnel protection ipsec profile DMVPN
DMVPN-Hub1(config-if)#

DMVPN-Hub2(config)#int tunnel 0
DMVPN-Hub2(config-if)#tun mode gre multipoint
DMVPN-Hub2(config-if)#bandwidth 1000
DMVPN-Hub2(config-if)#delay 1000
DMVPN-Hub2(config-if)#no ip redirects
DMVPN-Hub2(config-if)#ip mtu 1360
DMVPN-Hub2(config-if)#ip nhrp shortcut
DMVPN-Hub2(config-if)#tunnel key 101
DMVPN-Hub2(config-if)#tunnel protection ipsec profile DMVPN
DMVPN-Hub2(config-if)#

DMVPN-Client(config)#int tunnel 0
DMVPN-Client(config-if)#tun mode gre multipoint
DMVPN-Client(config-if)#bandwidth 1000
DMVPN-Client(config-if)#delay 1000
DMVPN-Client(config-if)#no ip redirects
DMVPN-Client(config-if)#ip mtu 1360
DMVPN-Client(config-if)#ip nhrp shortcut
DMVPN-Client(config-if)#tunnel key 101
DMVPN-Client(config-if)#tunnel protection ipsec profile DMVPN
DMVPN-Client(config-if)#

EzVPN-Server(config)#int tunnel 0
EzVPN-Server(config-if)#tun mode gre multipoint
EzVPN-Server(config-if)#bandwidth 1000
EzVPN-Server(config-if)#delay 1000
EzVPN-Server(config-if)#no ip redirects
EzVPN-Server(config-if)#ip mtu 1360
EzVPN-Server(config-if)#ip nhrp shortcut
EzVPN-Server(config-if)#tunnel key 101
EzVPN-Server(config-if)#tunnel protection ipsec profile DMVPN
EzVPN-Server(config-if)#
I should have also put the authentication command in there as well, as that will be the same for all of the routers:
DMVPN-Hub1(config-if)#ip nhrp authentication cisco

DMVPN-Hub2(config-if)#ip nhrp authentication cisco

DMVPN-Client(config-if)#ip nhrp authentication cisco

EzVPN-Server(config-if)#ip nhrp authentication cisco
OK, let's set up the IP addresses. We'll use the 192.168.1.0/24 network, and use .1 for DMVPN-Hub1, .2 for Hub2, .5 for DMVPN-Client and .6 for EZVPN-Server:
DMVPN-Hub1(config-if)#ip address 192.168.1.1 255.255.255.0

DMVPN-Hub2(config-if)#ip address 192.168.1.2 255.255.255.0

DMVPN-Client(config-if)#ip address 192.168.1.5 255.255.255.0

EzVPN-Server(config-if)#ip address 192.168.1.6 255.255.255.0
We need to set the tunnel source:
DMVPN-Hub1(config-if)#tunnel source lo0
DMVPN-Hub1(config-if)#
*Jul  1: %LINEPROTO-5-UPDOWN: Line protocol on Interface Tunnel0, changed state to up
*Jul  1: %CRYPTO-6-ISAKMP_ON_OFF: ISAKMP is ON
DMVPN-Hub1(config-if)# 

DMVPN-Hub2(config-if)#tunnel source lo0
DMVPN-Hub2(config-if)#
Jul  1: %LINEPROTO-5-UPDOWN: Line protocol on Interface Tunnel0, changed state to up
DMVPN-Hub2(config-if)#

DMVPN-Client(config-if)#tunnel source lo0
DMVPN-Client(config-if)#
*Jul  1: %LINEPROTO-5-UPDOWN: Line protocol on Interface Tunnel0, changed state to up
DMVPN-Client(config-if)#

EzVPN-Server(config-if)#tunnel source lo0
EzVPN-Server(config-if)#
*Jul  1: %LINEPROTO-5-UPDOWN: Line protocol on Interface Tunnel0, changed state to up
*Jul  1: %CRYPTO-6-ISAKMP_ON_OFF: ISAKMP is ON
EzVPN-Server(config-if)#
The tunnels should come up at this point, and ISAKMP will be turned on. Let's complete the hubs:
DMVPN-Hub1(config-if)#ip nhrp map multicast dynamic
DMVPN-Hub1(config-if)#ip nhrp network-id 101
DMVPN-Hub1(config-if)#ip nhrp redirect 
DMVPN-Hub1(config-if)#

DMVPN-Hub2(config-if)#ip nhrp map multicast dynamic
DMVPN-Hub2(config-if)#ip nhrp network-id 101
DMVPN-Hub2(config-if)#ip nhrp redirect
DMVPN-Hub2(config-if)#
We have a few commands to put on the clients.
DMVPN-Client(config-if)#ip nhrp map 192.168.1.1 10.1.16.200
DMVPN-Client(config-if)#ip nhrp map 192.168.1.2 10.1.26.200
DMVPN-Client(config-if)#ip nhrp map multicast 10.1.26.200
DMVPN-Client(config-if)#ip nhrp map multicast 10.1.16.200
DMVPN-Client(config-if)#ip nhrp nhs 192.168.1.1
DMVPN-Client(config-if)#ip nhrp nhs 192.168.1.2
DMVPN-Client(config-if)#ip nhrp network-id 101
DMVPN-Client(config-if)#

EzVPN-Server(config-if)#ip nhrp map 192.168.1.1 10.1.16.200
EzVPN-Server(config-if)#ip nhrp map 192.168.1.2 10.1.26.200
EzVPN-Server(config-if)#ip nhrp map multicast 10.1.26.200
EzVPN-Server(config-if)#ip nhrp map multicast 10.1.16.200
EzVPN-Server(config-if)#ip nhrp nhs 192.168.1.1
EzVPN-Server(config-if)#ip nhrp nhs 192.168.1.2
EzVPN-Server(config-if)#ip nhrp network-id 101
EzVPN-Server(config-if)#
We need a few ACLs to help. The problem is, that I have been quite messy with the ACLs on the firewalls so far, and they could probably do with a clean up. I think this is the reason for these errors:
DMVPN-Hub1#sh crypto isakmp sa
IPv4 Crypto ISAKMP SA
dst             src             state          conn-id status
4.4.4.4         5.5.5.5         MM_KEY_EXCH       1096 ACTIVE
4.4.4.4         5.5.5.5         MM_NO_STATE       1095 ACTIVE (deleted)
4.4.4.4         6.6.6.6         MM_KEY_EXCH       1097 ACTIVE
4.4.4.4         6.6.6.6         MM_NO_STATE       1094 ACTIVE (deleted)

IPv6 Crypto ISAKMP SA

DMVPN-Hub1
The traffic is passing to an extent, but definitely not all the traffic.

After (much) tidying up, this is what I am left with:
FO-ASA/C1(config)# sh run | i access-list                                                            
access-list Out->In extended permit icmp any host 4.4.4.4 
access-list Out->In extended permit icmp any object GlobalNats 
access-list Out->In extended permit esp host 5.5.5.5 host 4.4.4.4 
access-list Out->In extended permit esp host 6.6.6.6 host 4.4.4.4 
access-list Out->In extended permit udp host 5.5.5.5 host 4.4.4.4 eq isakmp 
access-list Out->In extended permit udp host 6.6.6.6 host 4.4.4.4 eq isakmp 
access-list In->Out extended permit icmp host 4.4.4.4 any 
access-list In->Out extended permit icmp object GlobalNats any 
access-list In->Out extended permit esp host 4.4.4.4 host 5.5.5.5 
access-list In->Out extended permit esp host 4.4.4.4 host 6.6.6.6 
access-list In->Out extended permit udp host 4.4.4.4 host 5.5.5.5 eq isakmp 
access-list In->Out extended permit udp host 4.4.4.4 host 6.6.6.6 eq isakmp 
FO-ASA/C1(config)# sh run | i access-group
access-group In->Out in interface Inside
access-group Out->In in interface outside
FO-ASA/C1(config)#  

FO-ASA/C2(config)# sh run | i access-list                                                 
access-list Out->In extended permit icmp any host 1.1.1.1 
access-list Out->In extended permit icmp any host 3.3.3.3 
access-list Out->In extended permit icmp any object-group GlobalNats 
access-list Out->In extended permit esp host 5.5.5.5 host 3.3.3.3 
access-list Out->In extended permit esp host 6.6.6.6 host 3.3.3.3 
access-list Out->In extended permit udp host 5.5.5.5 host 3.3.3.3 eq isakmp 
access-list Out->In extended permit udp host 6.6.6.6 host 3.3.3.3 eq isakmp 
access-list In->Out extended permit esp host 3.3.3.3 host 5.5.5.5 
access-list In->Out extended permit esp host 3.3.3.3 host 6.6.6.6 
access-list In->Out extended permit udp host 3.3.3.3 host 5.5.5.5 eq isakmp 
access-list In->Out extended permit udp host 3.3.3.3 host 6.6.6.6 eq isakmp 
access-list In->Out extended permit icmp host 1.1.1.1 any 
access-list In->Out extended permit icmp host 3.3.3.3 any 
access-list In->Out extended permit icmp object-group GlobalNats any 
FO-ASA/C2(config)# sh run | i access-group                                                
access-group Out->In in interface outside
access-group In->Out in interface inside
FO-ASA/C2(config)# 

Transparent(config)# sh run | i access-list 
access-list Out->In extended permit ospf host 10.1.7.1 host 224.0.0.5 
access-list Out->In extended permit ospf host 10.1.7.1 host 224.0.0.6 
access-list Out->In extended permit icmp host 10.1.7.1 host 10.1.7.2 
access-list Out->In extended permit ospf host 10.1.7.1 host 10.1.7.2 
access-list Out->In extended permit icmp host 1.1.1.1 any 
access-list Out->In extended permit icmp host 10.1.26.200 any 
access-list Out->In extended permit icmp host 10.1.16.200 any 
access-list Out->In extended permit icmp host 10.1.26.254 any 
access-list Out->In extended permit icmp host 10.1.16.254 any 
access-list Out->In extended permit esp host 10.1.16.200 host 5.5.5.5 
access-list Out->In extended permit esp host 10.1.26.200 host 5.5.5.5 
access-list Out->In extended permit esp host 10.1.16.200 host 6.6.6.6 
access-list Out->In extended permit esp host 10.1.26.200 host 6.6.6.6 
access-list Out->In extended permit udp host 10.1.16.200 host 5.5.5.5 eq isakmp 
access-list Out->In extended permit udp host 10.1.26.200 host 5.5.5.5 eq isakmp 
access-list Out->In extended permit udp host 10.1.16.200 host 6.6.6.6 eq isakmp 
access-list Out->In extended permit udp host 10.1.26.200 host 6.6.6.6 eq isakmp 
access-list In->Out extended permit ospf host 10.1.7.2 host 224.0.0.5 
access-list In->Out extended permit ospf host 10.1.7.2 host 224.0.0.6 
access-list In->Out extended permit ospf host 10.1.7.2 host 10.1.7.1 
access-list In->Out extended permit icmp host 10.1.7.2 host 10.1.7.1 
access-list In->Out extended permit icmp any host 1.1.1.1 
access-list In->Out extended permit icmp any host 10.1.26.200 
access-list In->Out extended permit icmp any host 10.1.16.200 
access-list In->Out extended permit icmp any host 10.1.26.254 
access-list In->Out extended permit icmp any host 10.1.16.254 
access-list In->Out extended permit esp host 5.5.5.5 host 10.1.16.200 
access-list In->Out extended permit esp host 5.5.5.5 host 10.1.26.200 
access-list In->Out extended permit esp host 6.6.6.6 host 10.1.16.200 
access-list In->Out extended permit esp host 6.6.6.6 host 10.1.26.200 
access-list In->Out extended permit udp host 5.5.5.5 host 10.1.16.200 eq isakmp 
access-list In->Out extended permit udp host 5.5.5.5 host 10.1.26.200 eq isakmp 
access-list In->Out extended permit udp host 6.6.6.6 host 10.1.16.200 eq isakmp 
access-list In->Out extended permit udp host 6.6.6.6 host 10.1.26.200 eq isakmp 
Transparent(config)# 
Transparent(config)# sh run | i access-group
access-group Out->In in interface Outside
access-group In->Out in interface Inside
Transparent(config)# 
 
This is much neater and more precise, but as far as DMVPN goes, still no dice, so let's think about the network. We have four DMVPN-speaking routers behind two firewalls. Whilst the transparent firewall is not performing NAT (because it's transparent), the other firewall is. So, let' enable NAT traversal, and open up port 4500 (nat traversal):
Transparent(config)# crypto isakmp nat-traversal 
Transparent(config)# access-list Out->In extended permit udp host 10.1.16.200 host 5.5.5.5 eq 4500
Transparent(config)# access-list Out->In extended permit udp host 10.1.26.200 host 5.5.5.5 eq 4500
Transparent(config)# access-list Out->In extended permit udp host 10.1.16.200 host 6.6.6.6 eq 4500
Transparent(config)# access-list Out->In extended permit udp host 10.1.26.200 host 6.6.6.6 eq 4500
Transparent(config)# access-list In->Out extended permit udp host 5.5.5.5 host 10.1.16.200 eq 4500
Transparent(config)# access-list In->Out extended permit udp host 5.5.5.5 host 10.1.26.200 eq 4500
Transparent(config)# access-list In->Out extended permit udp host 6.6.6.6 host 10.1.16.200 eq 4500
Transparent(config)# access-list In->Out extended permit udp host 6.6.6.6 host 10.1.26.200 eq 4500
Transparent(config)# 

FO-ASA/C1(config)# crypto isakmp nat-traversal 
FO-ASA/C1(config)# access-list Out->In extended permit udp host 5.5.5.5 host 4.4.4.4 eq 4500
FO-ASA/C1(config)# access-list Out->In extended permit udp host 6.6.6.6 host 4.4.4.4 eq 4500
FO-ASA/C1(config)# access-list In->Out extended permit udp host 4.4.4.4 host 5.5.5.5 eq 4500
FO-ASA/C1(config)# access-list In->Out extended permit udp host 4.4.4.4 host 6.6.6.6 eq 4500
FO-ASA/C1(config)# 

FO-ASA/C1(config)# changeto con C2
FO-ASA/C2(config)# crypto isakmp nat-traversal 
FO-ASA/C2(config)# access-list Out->In extended permit udp host 5.5.5.5 host 3.3.3.3 eq 4500
FO-ASA/C2(config)# access-list Out->In extended permit udp host 6.6.6.6 host 3.3.3.3 eq 4500
FO-ASA/C2(config)# access-list In->Out extended permit udp host 3.3.3.3 host 5.5.5.5 eq 4500
FO-ASA/C2(config)# access-list In->Out extended permit udp host 3.3.3.3 host 6.6.6.6 eq 4500
FO-ASA/C2(config)# 
This gets us exactly where we need to be:
DMVPN-Hub1#sh crypto isakmp sa
IPv4 Crypto ISAKMP SA
dst             src             state          conn-id status
4.4.4.4         5.5.5.5         QM_IDLE           1079 ACTIVE
4.4.4.4         6.6.6.6         QM_IDLE           1080 ACTIVE

IPv6 Crypto ISAKMP SA

DMVPN-Hub1#

DMVPN-Hub2#sh crypto isakmp sa
IPv4 Crypto ISAKMP SA
dst             src             state          conn-id status
3.3.3.3         6.6.6.6         QM_IDLE           1097 ACTIVE
3.3.3.3         5.5.5.5         QM_IDLE           1096 ACTIVE

IPv6 Crypto ISAKMP SA

DMVPN-Hub2#

DMVPN-Client#sh dmvpn
Legend: Attrb --> S - Static, D - Dynamic, I - Incomplete
        N - NATed, L - Local, X - No Socket
        T1 - Route Installed, T2 - Nexthop-override
        C - CTS Capable
        # Ent --> Number of NHRP entries with same NBMA peer
        NHS Status: E --> Expecting Replies, R --> Responding, W --> Waiting
        UpDn Time --> Up or Down Time for a Tunnel
==========================================================================

Interface: Tunnel0, IPv4 NHRP Details 
Type:Spoke, NHRP Peers:2, 

 # Ent  Peer NBMA Addr Peer Tunnel Add State  UpDn Tm Attrb
 ----- --------------- --------------- ----- -------- -----
     1 10.1.16.200         192.168.1.1    UP 00:09:05     S
     1 10.1.26.200         192.168.1.2    UP 00:01:09     S

DMVPN-Client#

EzVPN-Server#sh dmvpn | b Interface
Interface: Tunnel0, IPv4 NHRP Details 
Type:Spoke, NHRP Peers:2, 

 # Ent  Peer NBMA Addr Peer Tunnel Add State  UpDn Tm Attrb
 ----- --------------- --------------- ----- -------- -----
     1 10.1.16.200         192.168.1.1    UP 00:04:59     S
     1 10.1.26.200         192.168.1.2    UP 00:01:37     S

EzVPN-Server#

EzVPN-Server#ping 192.168.1.1 so tun 0
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.1.1, timeout is 2 seconds:
Packet sent with a source address of 192.168.1.6 
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 20/22/24 ms
EzVPN-Server#ping 192.168.1.2 so tun 0
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.1.2, timeout is 2 seconds:
Packet sent with a source address of 192.168.1.6 
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 17/20/24 ms
EzVPN-Server#

DMVPN-Client#ping 192.168.1.1 so tun0
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.1.1, timeout is 2 seconds:
Packet sent with a source address of 192.168.1.5 
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 20/22/28 ms
DMVPN-Client#ping 192.168.1.2 so tun0
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.1.2, timeout is 2 seconds:
Packet sent with a source address of 192.168.1.5 
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 18/20/22 ms
DMVPN-Client#
There is no huge mystery to dual-hub DMVPN, it is the same as single-hub, but with a couple more commands.

I covered DMVPN in VPNs and NAT for Cisco Networks, so have a read of that.

Now that the tunnels are up, we can run EIGRP across it:
DMVPN-Hub1(config)#int tun 0
DMVPN-Hub1(config-if)#no ip split-horizon eigrp 101
DMVPN-Hub1(config-if)#router eigrp 101
DMVPN-Hub1(config-router)#eigrp router-id 192.168.1.1
DMVPN-Hub1(config-router)#network 192.168.1.0 0.0.0.255
DMVPN-Hub1(config-router)#

DMVPN-Hub2(config)#int tun 0
DMVPN-Hub2(config-if)#no ip split-horizon eigrp 101
DMVPN-Hub2(config-if)#router eigrp 101
DMVPN-Hub2(config-router)#eigrp router-id 192.168.1.2
DMVPN-Hub2(config-router)#network 192.168.1.0 0.0.0.255
DMVPN-Hub2(config-router)#

DMVPN-Client(config)#int tun 0
DMVPN-Client(config-if)#no ip split-horizon eigrp 101
DMVPN-Client(config-if)#router eigrp 101
DMVPN-Client(config-router)#eigrp router-id 192.168.1.5
DMVPN-Client(config-router)#network 192.168.1.0 0.0.0.255 
DMVPN-Client(config-router)#
*Jul  2: %DUAL-5-NBRCHANGE: EIGRP-IPv4 101: Neighbor 192.168.1.1 (Tunnel0) is up: new adjacency
*Jul  2: %DUAL-5-NBRCHANGE: EIGRP-IPv4 101: Neighbor 192.168.1.2 (Tunnel0) is up: new adjacency
DMVPN-Client(config-router)#

EzVPN-Server(config)#int tun 0
EzVPN-Server(config-if)#no ip split-horizon eigrp 101 
EzVPN-Server(config-if)#router eigrp 101
EzVPN-Server(config-router)#eigrp router-id 192.168.1.6
EzVPN-Server(config-router)#network 192.168.1.0 0.0.0.255
EzVPN-Server(config-router)#
*Jul  2: %DUAL-5-NBRCHANGE: EIGRP-IPv4 101: Neighbor 192.168.1.2 (Tunnel0) is up: new adjacency
*Jul  2: %DUAL-5-NBRCHANGE: EIGRP-IPv4 101: Neighbor 192.168.1.1 (Tunnel0) is up: new adjacency
EzVPN-Server(config-router)#
Next up will be zone-based firewalls. I have not tried these before, so it should be interesting,

Volume 3: VPNs and NAT

With just a mere 45 days until my lab exam, I am happy to announce that the third volume in the Routing and Switching series; VPNs and NAT for Cisco Networks, has been published to the Kindle store today.

Getting the Kindle formatting has been much easier this time around, as I have used Kindle Textbook Creator, taking the printed version's PDF file, and converting straight from that.

The end result is that it looks the same as the print version (which should be available in a couple of days) which is out now.


This volume starts off with basic GRE tunnels, and build them into an IPSec-secured, optimized and tuned DMVPN network. We also look at "standard" site to site VPNs, before moving onto NAT, and IPv6 transition mechanisms.
I have kept the cost the same as the other volumes, and as usual, it's closely aligned with the CCIE Routing and Switching v5 syllabus. That said, I hope that it is accessible to readers of any level.

I am currently working on volume 4 (Multicast and QoS), and looking at volume 5 (Services). Volume 5 will, most likely, be the end of this series. I could go further, such as IPv6 and the IGPs, but to be honest I don't see that happening at the moment, as after volumes 4 and 5 I have another two books in mind, which are not (directly) related to the Routing and Switching track. This is, of course, unless anyone has any excellent ideas for more books, then I am all ears!

Anyway, I hope you enjoy it.

Design the next cover, win an Amazon voucher and a free copy of the next book!

Volume 2 is nearly completed, I have ordered the first proof copy so I can check layout, image quality, and how things line up compared to the first one (purely from a layout perspective). Beau, my technical editor, is still going through it, but it should be coming soon.

So, what's next?

Originally I had planned to to the IGPs (RIP, OSPF, EIGRP and IS-IS) next, but instead I have chosen to do "VPNs and NAT for Cisco Networks" for volume 3. In this volume I'll cover GRE, DMVPN, GETVPN and NAT technologies for both IPv4 and IPv6, I think this follows the progression nicer as we have started off with the global view of BGP, the larger scale enterprise with MPLS, and not we can start to look at connecting smaller sites together using VPNs, and with that NAT technologies. I think it'll lead on to the IGPs for volume 4 better this way.

Now I need a new cover design, and this is where you come in.

Have a look at the existing covers:



BGP (in my view) looks like a very interconnected world, highlighting the importance of BGP in our global internet, and MPLS looks like fewer connections, for the company to company networks.

For the next volume I am looking for something similar, abstract, yet understandable within the context of the book. I would like to use the same colors to keep within the running theme, or as this is a steady progression as we move into the IGPs, then maybe green, I like green as well. We don't have to stick with the circular "globe".

So if you want to have a go, then hopefully you can see what I am looking for. I would need this in a Photoshop PSD file of 7.5 x 9.25 (inches), I can handle the text part.

The end date for this will be December 1st.

The winner will receive a copy of the next book, and a £50 Amazon voucher (or equivalent in your local currency, i.e. $80 USD).

Email me: stu @ 802101 .com (remove the spaces...)

CCIE R+S V5 - DMVPN

So with the news about the change from the CCIE Routing and Switching V4 blueprint to the V5 many (i.e. some good sources) reckon that DMVPN will be on the new V5 blueprint.

What is DMVPN?

DMVPN stands for Dynamic Multipoint Virtual Private Network, what it does is allow multiple IPSec VPN connections with just one tunnel configuration, so for a site with one central "hub" and three other sites (or "spokes") instead of having three separate VPN configurations there is just one - it does mean that the traffic say from spoke1 to spoke3 needs to go through the hub, but from a configuration standpoint, life is much easier.

DMVPN is based on GRE (and we have covered GRE tunnels before, or mGRE if we are doing spoke-to-spoke tunnels), NHRP (next-hop resolution protocol) and IPSec (because VPN tunnels should be secure). DMVPN also requires a dynamic routing protocol, and CEF (Cisco Express Forwarding).

When it comes to the routing protocol to use within the tunnel EIGRP is preferred because it is an advanced distance vector protocol, better suited to the NBMA network that is built when using DMVPN.

DMVPN can be configured as Hub-and-Spoke or (using mGRE) Spoke-to-Spoke.

Consider the following topology:


We have a central site (called "Hub") and three different spoke at the bottom. In the middle is the cloud, which can be frame-relay or any other method of providing a connection between the hub and the spoke routers.

From the viewpoint of the routers, with our DMVPN in place, they will see the 10.10.1.0/24 network:


We start of with a basic configuration to provide connectivity:

Hub:
hostname Hub
!
interface Serial0/0
 ip address 10.25.1.2 255.255.255.0
!
ip route 10.35.1.0 255.255.255.0 10.25.1.1
ip route 10.45.1.0 255.255.255.0 10.25.1.1
ip route 10.55.1.0 255.255.255.0 10.25.1.1
Cloud:
hostname Cloud
!
interface Serial0/0
 ip address 10.25.1.1 255.255.255.0
!
interface Serial0/1
 ip address 10.35.1.1 255.255.255.0
!
interface Serial0/2
 ip address 10.45.1.1 255.255.255.0
!
interface Serial0/3
 ip address 10.55.1.1 255.255.255.0
Spoke1
hostname Spoke1
!
interface Loopback0
 ip address 10.50.1.1 255.255.255.0
!
interface Serial0/0
 ip address 10.35.1.2 255.255.255.0
!
ip route 10.25.1.2 255.255.255.255 10.35.1.1
Spoke 2
hostname Spoke2
!
interface Loopback0
 ip address 10.60.1.1 255.255.255.0
!
interface Serial0/0
 ip address 10.45.1.2 255.255.255.0
!
ip route 10.25.1.2 255.255.255.255 10.45.1.1
Spoke3
hostname Spoke3
!
interface Loopback0
 ip address 10.70.1.1 255.255.255.0
!
interface Serial0/0
 ip address 10.55.1.2 255.255.255.0
!
ip route 10.25.1.2 255.255.255.255 10.55.1.1
So you can see that we are starting off easy, with just basic connectivity from the Hub to each of the Spokes using the cloud to pass the traffic through. At this stage none of the spoke have any knowledge of each other.

DMVPN Tunnel configuration

The tunnel configuration is much like a standard GRE tunnel but with a couple of additional commands.

The Hub is where everything points to, and we associate the tunnel with a network-id (this is the NBMA identifier), setting the mode as gre multipoint. The spokes map the tunnel IP set on the Hub (10.10.1.1) to the external IP address of the Hub (10.25.1.2), and set this as the next-hop-server (ip nhrp nhs 10.10.1.1).

Hub tunnel:
interface Tunnel0
 ip address 10.10.1.1 255.255.255.0
 no ip redirects
 ip mtu 1416
 no ip next-hop-self eigrp 1
 ip nhrp map multicast dynamic
 ip nhrp network-id 1
 no ip split-horizon eigrp 1
 tunnel source 10.25.1.2
 tunnel mode gre multipoint
Spoke 1 tunnel:
interface Tunnel0
 ip address 10.10.1.2 255.255.255.0
 no ip redirects
 ip mtu 1416
 no ip next-hop-self eigrp 1
 ip nhrp map 10.10.1.1 10.25.1.2
 ip nhrp map multicast 10.25.1.2
 ip nhrp network-id 1
 no ip split-horizon eigrp 1
 ip nhrp nhs 10.10.1.1
 tunnel source 10.35.1.2
 tunnel mode gre multipoint
Spoke 2 tunnel
interface Tunnel0
 ip address 10.10.1.3 255.255.255.0
 no ip redirects
 ip mtu 1416
 no ip next-hop-self eigrp 1
 ip nhrp map 10.10.1.1 10.25.1.2
 ip nhrp map multicast 10.25.1.2
 ip nhrp network-id 1
 no ip split-horizon eigrp 1
 ip nhrp nhs 10.10.1.1
 tunnel source 10.45.1.2
 tunnel mode gre multipoint
Spoke 3 tunnel:
interface Tunnel0
 ip address 10.10.1.4 255.255.255.0
 no ip redirects
 ip mtu 1416
 no ip next-hop-self eigrp 1
 ip nhrp map 10.10.1.1 10.25.1.2
 ip nhrp map multicast 10.25.1.2
 ip nhrp network-id 1
 no ip split-horizon eigrp 1
 ip nhrp nhs 10.10.1.1
 tunnel source 10.55.1.2
 tunnel mode gre multipoint
We can check that our DMVPN tunnel is working using the "sh dmvpn" command:
Hub#sh dmvpn | beg Interface

Interface: Tunnel0, IPv4 NHRP Details
Type:Hub, NHRP Peers:3,

 # Ent Peer NBMA Addr  Peer Tunnel Add State UpDn Tm  Attrb
 ----- --------------- --------------- ----- -------- -----
   1   10.35.1.2       10.10.1.2       UP    00:06:19  D
   1   10.45.1.2       10.10.1.3       UP    00:05:06  D
   1   10.55.1.2       10.10.1.4       UP    00:04:28  D
We can also use basic ping tests:
Hub#ping 10.10.1.2

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.1.2, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 20/20/20 ms
Hub#ping 10.10.1.3

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.1.3, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 16/20/24 ms
Hub#ping 10.10.1.4

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.1.4, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 20/20/20 ms

Adding IPSec to DMVPN

One of the requirements of DMVPN is IPSec, and this is quite easy to add, the same configuration can go on the Hub and the three spokes.The major thing to point out is that we associate the "dmvpn123" key with any IP address by using the 0.0.0.0 0.0.0.0 address and subnet.
crypto isakmp policy 10
 encryption 3des
 hash md5
 authentication pre-share
crypto isakmp key dmvpn123 address 0.0.0.0 0.0.0.0
!
!
crypto ipsec transform-set MyIPSEC esp-3des
!
crypto ipsec profile DMVPN
 set transform-set MyIPSEC
!
interface Tunnel0
 tunnel protection ipsec profile DMVPN

Adding EIGRP to DMVPN

DMVPNs require a routing protocol within the tunnel (otherwise they would be rather useless), and this is a simple case of adding one!
Hub#sh run | beg router
router eigrp 1 
 network 10.0.0.0
 no auto-summary

Spoke1#sh run | beg router
router eigrp 1
 network 10.0.0.0
 no auto-summary

Spoke2#sh run | beg router
router eigrp 1
 network 10.0.0.0
 no auto-summary

Spoke3#sh run | beg router
router eigrp 1
 network 10.0.0.0
 no auto-summary

Bringing all of DMVPN together

With all of the nuits and bolts in place now we should have some good visilibilty between our spoke routers. We should see routers learned through EIGRP (indicated with a "D") and be able to ping to the loop back addresses that we configured at the start.
 
Spoke1#sh ip route | beg Gateway
Gateway of last resort is not set

   10.0.0.0/8 is variably subnetted, 10 subnets, 2 masks
C    10.10.1.0/24 is directly connected, Tunnel0
L    10.10.1.2/32 is directly connected, Tunnel0
D    10.25.1.0/24 [90/27392000] via 10.10.1.1, 00:09:46, Tunnel0
S    10.25.1.2/32 [1/0] via 10.35.1.1
C    10.35.1.0/24 is directly connected, Serial0/0
L    10.35.1.2/32 is directly connected, Serial0/0
C    10.50.1.0/24 is directly connected, Loopback0
L    10.50.1.1/32 is directly connected, Loopback0
D    10.60.1.0/24 [90/28288000] via 10.10.1.3, 00:08:06, Tunnel0
D    10.70.1.0/24 [90/28288000] via 10.10.1.4, 00:07:02, Tunnel0
Spoke1#sh dmvpn | beg Interface
Interface: Tunnel0, IPv4 NHRP Details
Type:Spoke, NHRP Peers:1,

 # Ent Peer NBMA Addr  Peer Tunnel Add State UpDn Tm  Attrb
 ----- --------------- --------------- ----- -------- -----
   3   10.25.1.2       10.10.1.1       UP    00:34:25 S
                       10.10.1.3       UP    00:02:07 D
                       10.10.1.4       UP    00:02:11 D
Spoke1#ping 10.70.1.1

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.70.1.1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 40/43/48 ms
Spoke1#ping 10.60.1.1

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.60.1.1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 40/44/48 ms
Spoke1#

Hub-and-spoke or Spoke-to-Spoke?

Depending on the requirements you can either setup a hub-to-spoke or spoke-to-spoke topology. We have been using spoke-to-spoke through this, we can see this using the command "sh ip nhrp", because tunnels will drop if there is no traffic (apart from the one to the hub) we can see what NHRP believes to be the next hop for the end-point - so with the tunnel from Spoke1 to Spoke3 down we can issue a ping and see the tunnel come back up again - also showing the tunnel is a spoke-to-spoke.
Spoke1#sh ip nhrp
10.10.1.1/32 via 10.10.1.1
   Tunnel0 created 01:15:40, never expire 
   Type: static, Flags: used 
   NBMA address: 10.25.1.2 
Spoke1#ping 10.70.1.1      

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.70.1.1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 40/40/40 ms
Spoke1#sh ip nhrp    
10.10.1.1/32 via 10.10.1.1
   Tunnel0 created 01:15:47, never expire 
   Type: static, Flags: used 
   NBMA address: 10.25.1.2 
10.10.1.4/32 via 10.10.1.4
   Tunnel0 created 00:00:01, expire 00:03:03
   Type: dynamic, Flags: temporary
   NBMA address: 10.25.1.2 
Spoke1#
We can, should we wish make it a true hub-to-spoke topology with adding the line "ip nhrp server-only" to the spokes
With our configuration before we can see that the tunnel to the Hub always remains up. We can ping Spoke3 and confirm that another tunnel is created:
Spoke2#sh dmvpn | beg Interface
Interface: Tunnel0, IPv4 NHRP Details
Type:Spoke, NHRP Peers:1,

 # Ent  Peer NBMA Addr Peer Tunnel Add State  UpDn Tm Attrb
 ----- --------------- --------------- ----- -------- -----
     1       10.25.1.2       10.10.1.1    UP 00:01:18     S

Spoke2#ping 10.70.1.1

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.70.1.1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 40/43/48 ms
Spoke2#sh dmvpn | beg Interface
Interface: Tunnel0, IPv4 NHRP Details
Type:Spoke, NHRP Peers:1,

 # Ent  Peer NBMA Addr Peer Tunnel Add State  UpDn Tm Attrb
 ----- --------------- --------------- ----- -------- -----
     2       10.25.1.2       10.10.1.1    UP 00:01:28     S
                             10.10.1.4    UP 00:00:03     D
If we then go into the interface and add the "ip nhrp server-only" command we can confirm that we still have reachability to Spoke3, but only have one tunnel:
Spoke2(config)#int tunnel 0
Spoke2(config-if)#ip nhrp server-only
Spoke2(config-if)#exit
Spoke2(config)#exit
Spoke2#sh dmvp | beg Interface
Interface: Tunnel0, IPv4 NHRP Details
Type:Spoke, NHRP Peers:1,

 # Ent  Peer NBMA Addr Peer Tunnel Add State  UpDn Tm Attrb
 ----- --------------- --------------- ----- -------- -----
     1       10.25.1.2       10.10.1.1    UP 00:02:24     S

Spoke2#ping 10.70.1.1

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.70.1.1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 40/42/48 ms
Spoke2#sh dmvp | beg Interface
Interface: Tunnel0, IPv4 NHRP Details
Type:Spoke, NHRP Peers:1,

 # Ent  Peer NBMA Addr Peer Tunnel Add State  UpDn Tm Attrb
 ----- --------------- --------------- ----- -------- -----
     1       10.25.1.2       10.10.1.1    UP 00:02:31     S

There are some more commands we can use to confirm that our tunnels are looking how they should:
Spoke2#sh ip nhrp
10.10.1.1/32 via 10.10.1.1
   Tunnel0 created 00:14:31, never expire
   Type: static, Flags: used
   NBMA address: 10.25.1.2
Spoke2#sh ip cef 10.70.1.0
10.70.1.0/24
  nexthop 10.10.1.4 Tunnel0
So we have full reachability between the spokes! Pretty neat, and so much easier than creating three different VPNs on each router! It is pretty simple really, if you have created a GRE tunnel before then really we are only looking at a couple of extra lines - and these extra few lines can be copied from one spoke router and pasted onto every other spoke router because they are identical!