DMVPN phase 3 migration with Central hub

I am looking at migrating my phase 2 DMVPN network to phase 3. The current network contains 3 regional hubs each serving approx 100 spokes. The end goal is to be able to build spoke to spoke tunnels between sites that are homed to hubs in different regions. I understand from reading the document "Migrating from Dynamic Multipoint VPN Phase 2 to Phase 3" that phase 3 regional hubs can be linked in a heirarchy via a cental hub but there is no detail in the doc and I have not been able to find a white paper that deals with this specifically. Does anyone have experience with this topology or have documention that deals with central hub configuration and deployment?
Regards,
Mike

Mike,
Might be a good idea to run this by your SE.
In general phase 3 design with phase 3 images you need to remember you will follow routing for NHRP, i.e. if you summarize properly you will scale pretty decently (with or without regional hub).
What are the benefits of phase 3 design comapred to phase 2 design that you're trying to achieve?
Marcin.
P.S. If we're talking about same migtation document
http://www.cisco.com/en/US/prod/collateral/iosswrel/ps6537/ps6586/ps6660/ps6808/prod_white_paper0900aecd8055c34e_ps6658_Products_White_Paper.html
it's an un-maintained marketing document, all our efforts to correct some of the problems there (ip ospf network point-to-multipoint for example) so far have not come to fruition.

Similar Messages

  • Fiori CRM apps with central hub deployment

    Hello Experts,
    We are looking to configure Fiori CRM apps in our landscape with central hub deployment option. Our CRM backend and frontend server (Gateway) are 2 separate systems.
    The CRM backend system (CRM 7.0 EHP3) is running NW 7.4 whereas the frontend server where we have installed the Gateway component is running NW 7.31. Can we go ahead and install the CRM UI components on our frontend server or is it mandatory that the frontend server also runs NW 7.4?
    Regards,
    Saurabh
    Tags edited by: Michael Appleby

    Hi Masa,
    The link you mentioned gives details about the required SAP Gateway Components for NetWeaver 7.3 & 7.4, but does not mention anywhere whether the NetWeaver version of the backend business suite system should necessarily be NW7.4 if we have front-end system on NW7.4.
    I am looking to clarify the doubt regarding whether both front-end and back-end systems should be on the same NetWeaver release or it is fine to have front-end on 7.31 and back-end on 7.4
    Regards,
    Saurabh

  • Dual-DMVPN Design with Dual Hubs on a single router ??

    Hi All,
    In DMVPN, in Dual-DMVPN Design with Dual Hubs , can a single router perform the role of dual hubs.
    The router has two different internet links. It is intended that when one link goes down, spokes shud connect to the same router onto the other active internet connection. Is this possible ?

    Since no one has answered yet, I'll give you the practical answer.
    You'll have issues with IPSec and static routing. "DMVPN" itself probably wouldn't have an issue, but it would depend on IPSec and routing to work.
    It is easier, by far, to put in a second router. And when you factor in your time to try to make it work (and it may not work), the second router is less expensive.
    Rob

  • Does 7206VXR (NPE-G2) with c7200p-advipservicesk9-mz.150-1.M7 supports DMVPN phase 3?

    Hello,
    We have a cisco 7206VXR (NPE-G2) with IOS c7200p-advipservicesk9-mz.150-1.M7.bin.
    We want to implement DMVPN phase 3 but the command "show ip nhrp shortcut" is not included.
    does 7206VXR (NPE-G2) with c7200p-advipservicesk9-mz.150-1.M7 supports DMVPN phase 3?
    Is there any other command to verify the DMVPN phase 3 implementation?
    Thank you in advance!

    Hi Inayath,
    We are applying policy-map on user virtual-interface via radius attributes.
    Cisco-Avpair+="lcp:interface-config#1=service-policy input 256k"
    Cisco-Avpair+="lcp:interface-config#2=service-policy output 256k"
    Below is the relevant configuration for cisco router.
    aggri03#sh policy-map 256k
      Policy Map 256k
        Class 256k
         police cir 520000 bc 32000
           conform-action transmit
           exceed-action drop
    aggri03#sh run int virtual-te1
    Building configuration...
    Current configuration : 398 bytes
    interface Virtual-Template1
     mtu 1492
     ip unnumbered Loopback100
     no ip redirects
     no ip unreachables
     no ip proxy-arp
     no logging event link-status
     peer default ip address pool poolname
     no snmp trap link-status
     keepalive 60
     ppp authentication pap callin
     ppp ipcp dns 203.187.x.y 203.187.x.y
     ppp timeout ncp 30
     ppp timeout authentication 20
     ppp timeout idle 480
    end
    Below is the complete log line on router.
    Sep  3 16:41:31: %SW_MGR-3-CM_ERROR_FEATURE_CLASS: Connection Manager Feature Error: Class SSS: (QoS) - install error, ignore.
    -Traceback= 4A9C88 4AAC20 4AB350 12B6040 12C8B38 2C2F24C 2C2F2FC 12C8E0C 12C9000 12C94D0 12B4788 12B4D40 12B4E84 12AFEB0 12B02FC
    Please let me know if you want further information & thanks for your inputs.
    Thanks,
    Nilesh.

  • DMVPN Phase 3 dual cloud Spoke-to-Spoke communication

    Hello,
    I'd like to confirm/verify if Phase 3 allows Spokes in different DMVPN domains to communicate directly or is traffic from Spoke-DMVPN-A routed across the Hubs to Spoke-DMVPN-B? Any authoritative documentation on CCO on this specific scenario is greatly appreciated.
    Thanks.
    -Mike

    Mike, 
    I might be off, not working with VPNs for a year now, but here goes. 
    It really depends on what is a domain for you. Remember that NHRP network ID is locally significant.
    Ultimately same network ID allows NHRP resolution requests to jump between different tunnels. 
    If network ID is different then the "domain" is different and NHRP should not flow between. 
    For the rest it's all based on routing, it's just a question of making conscious design choices before deploying and a bit of testing. 
    M.

  • 12.4(11) or 12.4(15) for DMVPN Phase 3

    Hi
    We are to plan a migration from DMVPN Phase 2 12.3(11) to a DMVPN Phase 3 architecture (about 300 spokes).
    Does someone have experience any issues with the following IOS version in a DMVPN Phase 3 architecture ?
    12.4 (11) or
    12.4 (15).
    Thank you very much for your help

    Are you referring to 12.4 Mainline code or 12.4T code. The reason I ask is, I have not seen a 12.4(11) 12.4(15) on cisco.com.
    If you are referring to 12.4(11)T or 12.4(15)T, you may want to look at CSCsj34699 which is resolved in 12.4(15)T1. Also, take a look at the 12.4T release notes for additional information.
    http://www.cisco.com/univercd/cc/td/doc/product/software/ios124/124relnt/xprn124t/124tcavs.htm
    Regards,
    Arul

  • I want to use my Time Capsule as a central 'hub/hard-drive' in order to keep all my working files in one place. I then plan to use my laptops/desktops as peripheral devices for editing and creation of these files. Is it possible? Create a personal cloud?

    I want to use my Time Capsule as a central 'hub/hard-drive' in order to keep all my working files in one place. I then plan to use my laptops/desktops as peripheral devices for editing and creation of these files. Is it possible? To create a personal cloud?
    Can someone advise as to whether i can do the following:
                                Future Internet connection -------------------TIME CAPSULE (containing all files) -------------- Backed up on the WD 2T Hard-drive I have
                                      (not connected yet)                                         I                                                          (*connected to timecapsule physically)
                                                                                                            I
                    I                                         I                                                I                                                              I                                                I
          Macbook Pro                             iMac                                       HP (PC)                                             OLD Macbook Pro                         iPhone
    (used for remote working)       (Used for home working)     (used for heavy CAD and rendering)    (not being used for anything at the moment)        (& iPods)
    I am looking to have all my files in one place as i am hopelessly disorganised. I know the online clouds are a good solution (used Dropbox at work and uni for 3 years) however i am wanting to create my own 'dropbox/icloud' at home. So whenever i get back home with my laptop, any work i have been working on whilst out that day is updated to the timecapsule, and then ultimately as i turn on the other devices, they update to those newer versions of the files. Please tell me that the 3TB time capsule i have can do this, otherwise it feels rather overpriced as a wireless storage device?
    Another note (to those in the know) If i am to be working on large files (REVIT/SOLIDWORKS/KEYSHOT/CREO/AUTOCAD) - is the timecapsule connection good enough to support editing and updating these files?
    I know i may be asking a question that many have before, but as a bit of a technical novice I wanted a clear-cut answer to my specific circumstances. Your help is greatly appreciated.
    (*can i use this WD hard-drive that is connected to the Time Capsule as a back up? so that the time machine back-ups/any back ups are also backed up onto this one? can the WD be a backup for the TC?)
    Kind Regards
    Joe

    The diagram was supposed to look more like this......
    Internet ---------TIME CAPSULE(containing all files) --------WD 2T Harddrive
                                                I
         I                           I                          I                            I                                   I
    Macbook Pro         iMac                 HP (PC)            OLD Macbook Pro           iPhone
    Sorry!
    Regards
    Joe

  • Routing issue between two satellites sites and one central hub

    Hi,
    I have 3 Ad sites with one exchange 2010 hub,cas,mailbox server on each sites.
    One of this site (site A) is central Hub and the two other sites  ( B and C) are two satellites of site A.
    The is no connectivity between site B and C, only connectivity between A and B, and A and C.
    When I send a mail from Site B to Site C, Exchange try to deliver the mail directly to site C and don't pass to site A to deliver to site C, some mail stay in queue in site B, and the the queue is in retry.
    I flag the site A as HUB.
    Site toplogy is correct and the cost too.
    Can someone help me??
    Thanks

    what are your AD costs between A, B and C?
    In Exchange 2010, each message recipient is always associated with only one Active Directory site, and there is only one least cost routing
    from the source Active Directory site to the destination Active Directory site
     If the least-cost routing path to the primary site contains any hub sites, the message must be
    routed through the hub sites

  • Usb laser printing, HD's with integral hubs, and open doors to network?

    Bought a N capable base station and an airport express this week as I have multiple minis and a macbook and wish to put my itunes onto a central drive and use wireless printing.
    Spent an “interesting” evening last night setting up, and I seem to have worked out how to use itunes via aliases etc.
    But – when I try to print, the dialogue box comes up, the laser printer (Samsung 2550) starts up, but fails to print.
    My set up is as follows – Iomega 320gb mini HD (powered) plugged into the USB on the base station and then the laser and my inkjet plugged into the USB sockets on the HD (its one of those which has an integral USB and FW hub built in).
    Now, as it was very late in the evening, I didn’t do any more trouble shooting, but am intrigued as to why the printer would not print. The log says that the print job has been completed, but nothing comes out. I disconnected the printers from the hd hub and then disconnected the HD. I then plugged the printer directly into the base station, but it still doesn’t work.
    Annoyingly enough, the printer worked fine the previous night when I was using it with the usb on the airport express alone (hadn’t bought the base station at this point).
    The computer(s) “see” the laser printer without difficulty, so I see no reason why it should not print using the base station.
    One thing which occurs to me is to plug a powered USB hub into the base station, and then separately plug the HD and the Laser into sockets on this hub, rather than using the integral hub of the HD. Again, I cant see why this should be necessary but I’ll give it a try.
    Any thoughts re this?
    One Last Thing…
    The main reason for buying the kit is to cover a “weak spot” in the house for wifi. Hence the idea was to connect my modem/router via Ethernet to the base station, and then use the airport express as a WDS to effectively re-broadcast the signal and hopefully provide maximum signal strength throughout the house.
    My question is – having used the airport utility to do this, am I right in presuming that the airport express then becomes effectively “invisible” and hence when I use my mini in the weak spot to log onto a network via airport, I should only see the SSID of my main base station (although in reality I will be accessing it via the airport express). I think this must be right because when I added the airport express the signal strength in the weak area of the house went to the max.
    My base station uses WAP protection but I don’t appear to have any protection set up on the airport express (which I realise is a router in its own right). Do I need to add protection to the airport express to prevent access to my overall network? In otherwords, is an unprotected airport express acting as a WDS, effectively an open back door to the network? Would a neighbour etc be able to pick up my network SSID being broadcast by the airport express and log onto that without the WAP password?
    Finally what is the difference between the airport express being a remote or a relay station. I would have thought that to act as a network extender, it should be set to relay, but the default appears to be remote. The Apple help sections don’t appear to distinguish between functionality, merely state the options.
    Any help/advice gratefully accepted
    Airport extreme, mac minis    

    I then plugged the printer
    directly into the base station, but it still doesn’t
    work.
    You need to get this to work first. Otherwise forget it to work with a Hub. Turn the printer on FIRST. Then turn on the base station.
    One thing which occurs to me is to plug a powered USB
    hub into the base station, and then separately plug
    the HD and the Laser into sockets on this hub, rather
    than using the integral hub of the HD. Again, I cant
    see why this should be necessary but I’ll give it a
    try.
    Direct connection and powered USB Hub are the only supported configurations by Apple. I've had no problem with attaching up to 7 separate devices on a $20 powered hub. Having a "integrated hub" like you describe may theoretically work, but it is not the same thing as a separate hub.
    My question is – having used the airport utility to
    do this, am I right in presuming that the airport
    express then becomes effectively “invisible” and
    hence when I use my mini in the weak spot to log onto
    a network via airport, I should only see the SSID of
    my main base station (although in reality I will be
    accessing it via the airport express).
    If you use WDS or "extend" the network, all base stations will still broadcast the SSID.
    My base station uses WAP protection
    You must mean WEP or WPA. There is no WAP protection.
    but I don’t
    appear to have any protection set up on the airport
    express (which I realize is a router in its own
    right). Do I need to add protection to the airport
    express to prevent access to my overall network? In
    other words, is an unprotected airport express acting
    as a WDS, effectively an open back door to the
    network? Would a neighbor etc be able to pick up my
    network SSID being broadcast by the airport express
    and log onto that without the WAP password?
    Yes, even if you turn SSID broadcast off, the SSID is broadcasted during the transactions and it will be easily detected using iStumbler. An yes you are letting a nice open back door for your neighbors.

  • DMVPN Phase 3 ip nhrp short / ip nhrp redirect missing

    Dear All, we are trying to setup DMVPN Phase 3 and need to enter the commands ip nhrp shortcut and ip nhrp redirect which is not possible on Cisco 1841 routers - IOS version advipservicesk9-mz.124-25f.bin
    On a cisco 1812 c181x-advipservicesk9-mz.124-24.T4.bin we can enter the commands.
    Out aommands 1841:
    Router 1(config-if)#ip nhrp ?
      authentication  Authentication string
      holdtime        Advertised holdtime
      interest        Specify an access list
      map             Map dest IP addresses to NBMA addresses
      max-send        Rate limit NHRP traffic
      network-id      NBMA network identifier
      nhs             Specify a next hop server
      record          Allow NHRP record option
      registration    Settings for registration packets.
      responder       Responder interface
      server-only     Disable NHRP requests
      trigger-svc     Create NHRP cut-through based on traffic load
      use             Specify usage count for sending requests
    Output commands 1812:
    Router 2(config-if)#ip nhrp ?
      authentication  Authentication string
      cache           NHRP Cache related commands.
      group           NHRP group name
      holdtime        Advertised holdtime
      interest        Specify an access list
      map             Map dest IP addresses to NBMA addresses
      max-send        Rate limit NHRP traffic
      network-id      NBMA network identifier
      nhs             Specify a next hop server
      record          Allow NHRP record option
      redirect        Enable NHRP redirect traffic indication
      registration    Settings for registration packets.
      responder       Responder interface
      server-only     Disable NHRP requests
      shortcut        Enable shortcut switching
      trigger-svc     Create NHRP cut-through based on traffic load
      use             Specify usage count for sending requests
    This is the information I found on the Cisco web page: "In Cisco IOS Software Release 12.4(6)T, DMVPN Phase 3 was introduced". Now I am wondering which software I shall use for the Cisco 1841 as we already use a higher version: advipservicesk9-mz.124-25f.bin
    I appreciate your help
    Thank you
    Nikola

    Nikola,
    Let's start wit this:
    http://en.wikipedia.org/wiki/Cisco_IOS#Versioning
    Than what you need to understand is that T train is where we put all the new fearures. Mainline is one we rebuild with usuall no big changes, i.e. main focus is stability with less features.
    That being said 12.4(25) might have a higher number than 12.4(24)T, but it will not contains some features.
    Marcin

  • Netweaver central hub VS Embedded system

    What is the best approach.
    Is it good to have a Netweaver gateway as central hub and access all the other systems from there.
    I mean if i have a server with SAP AS 7.0 and use a central hub approach, Can i have all the features which i can get with the system having 7.4 AS ABAP SP11 and generating the Gateway there itself.
    Will there be any limitations in the Central hub approach ?

    Keep in mind that Gateway HUB has to be at equal or greater than the version at Gateway BEP Component. So when you set-up HUB system, ensure that you do not connect any backend system having latest components. You may achieve it by updating HUB system regularly.
    About which is best,  Andreas has written a very good document.
    SAP Gateway deployment options in a nutshell

  • Open Hub: How-to doc "How to Extract data with Open Hub to a Logical File"

    Hi all,
    We are using open hub to download transaction files from infocubes to application server, and would like to have filename which is dynamic based period and year, i.e. period and year of the transaction data to be downloaded. 
    I understand we could use logical file for this purpose.  However we are not sure how to have the period and year to be dynamically derived in filename.
    I have read in sdn a number of posted messages on a similar topic and many have suggested a 'How-to' paper titled "How to Extract data with Open Hub to a Logical Filename".  However i could not seem to be able to get document from the link given. 
    Just wonder if anyone has the correct or latest link to the document, or would appreciate if you could share the document with all in sdn if you have a copy.
    Many thanks and best regards,
    Victoria

    Hi,
    After creating open hub press F1 in Application server file name text box from the help window there u Click on Maintain 'Client independent file names and file paths'  then u will be taken to the Implementation guide screen > click on Cross client maintanance of file name > create a logical file path by clicking on new entiries > after creating logical file path now go to Logical file name definition there give your Logical file , name , physical file (ur file name followed by month or year what ever is applicable (press f1 for more info)) , data format (ASC) , application area (BW) and logical path (choose from F4 selection which u have created first), now goto Assignment of  physical path to logical path > give syntax group >physical path is the path u gave at logical file name definition.
    however we have created a logical path file name to identify the file by sys date but ur requirement seems to be of dynamic date of tranaction data...may u can achieve this by creating a variable. U can see the help from F1 that would be of much help to u. All the above steps i have explained will help u create a dynamic logical file.
    hope this helps u to some extent.
    Regards

  • Extract Data with OPEN HUB to a Logical Filename

    Hi Experts,
    Can anybody help me in sending the link for How to guide...Extract Data with OPEN HUB to a Logical Filename?
    Thanks in advance.
    BWUser

    Hi,
    check this links...
    http://searchcrm.techtarget.com/generic/0,295582,sid21_gci1224995,00.html
    https://www.sdn.sap.com/irj/servlet/prt/portal/prtroot/docs/library/uuid/e698aa90-0201-0010-7982-b498e02af76b
    https://www.sdn.sap.com/irj/servlet/prt/portal/prtroot/docs/library/uuid/1570a990-0201-0010-1280-bcc9c10c99ee
    hope this may help you ..
    Regards,
    shikha

  • Need help to import and syncronize HCM pagelets with Interaction Hub, how can I do that?

    Hi,
    I need help to import and synchronize HCM pagelets with Interaction Hub, how can I do that? The default page "Select Remote Content" of the WorkCenter "Unified Navigation WorkCenter" is not working as well, when I run the import/sync button I get the following error message:
    Integration Gateway: General Connection Failed (158,10836)
    This error is thrown when there is no valid response.
    Possible errors include:
    Bad gateway URL
    Sync Service Timeout set and Service actually timed out.
    Java exception thrown - Check Application Server for possible Java exception

    Do you have integration configured between the two systems?  It sounds like you don't from the error.  Here is a walk-through on setting up Unified Navigation although it assumes you have integration already working.  If you haven't done that, it's documented a hundred different places.
    http://remotepsadmins.com/2013/03/04/peoplesoft-unified-navigation-with-peoplesoft-applicatations-portal-interaction-hub/

  • Need help with open hub

    Hi eveybody,
             I was trying to wok with open hub. Created infospoke, destination i gave was a csv file named d:/openmara.csv path, saved and activated the info spoke. I went to d:/ to view the uploaded files, two file was created, when i try to open a file it says "unable to read" , when i tried to open the second one i could open the file and see some datas but not in a correct format, why is that?
    Then i tried to load the data in database, so in the infospoke i selected the option for destination as database,saved and activated the infospoke, now where should i go to see the uploaded datas physically?
    Could anyone help me with this.
    Thanks,
    RR.

    Hi,
    Thanks for the reply. I created a infospoke and destination was database option. Opened the se16 gave the table name which starts with /bic/....(please correct me if i am wrong),then the initial screen of se16 came up with all the fields , but when i executed it, the table is empty.Could you say why it is happening.
    Thanks,
    RR.

Maybe you are looking for

  • Print Queue wont open in Snow Leopard

    After upgrading I finally got my Epson 3800 to work but although I can open the utilities button I can't open the print queue. Tried resetting, downloading new driver and repair to preferences but nothing. The printer does not show up in the dock. It

  • Video Chat won't work in Germany.

    Hi, I am new to the discussions board, and I just recently bought an iSight camera so I can chat with and see my family while I'm studying abroad in Munich, Germany. Every time we attempt to do a Video Chat session the window pops up, and says it is

  • How to resubmit the form when back button pressed

    Hi, In my application, iam implementing searching, when i submitting the form, i got some records and i navigated all the results through next and previous buttons. Problem occurs when i clicked on back button, it is showing "page expires and asking

  • Satellite Pro A60 USB power shortage?

    I can only use 2 out of 3 USB ports. Seperately all 3 USB ports work fine (devices also) but I cant use the 2 on the backside at the same time. I use one USB stick and one USB mouse. I HAVE to use the USB port at the right side, otherwise it wont wor

  • Where can I complain about the service in a Thailand ?

    I got a very bad service from the main office in thailand. Where can I complain as a royal costumer of Apple ?