The scenario
A distributed enterprise needs secure, scalable branch connectivity using DMVPN dynamic hub-and-spoke architecture, with a central hub at HQ and multiple branch spokes that can dynamically establish tunnels.
What is in this drawing
Read the decisions behind it.
01
Deploy a hub router at HQ with firewall and NHRP server to terminate mGRE/IPsec tunnels from all spokes.
02
Use DMVPN dynamic hub-and-spoke tunnels from each branch router to the hub, with NHRP enabling direct spoke-to-spoke connectivity as needed.
03
Keep branch LAN segments simple with access switches, PCs, APs, and IP phones behind each spoke router.
Reusable for any multi-site enterprise network that needs VPN-based WAN connectivity with dynamic spoke-to-spoke routing and a hub-and-spoke overlay.
More like this
Other examples in this family.
Loading drawing…
Site-to-Site VPN: AWS VPC to On-Premises Data CenterNetwork DiagramOpen →Loading drawing…
Multi-site IPsec VPN Between Headquarters and Remote Branch OfficesNetwork DiagramOpen →Loading drawing…
Redundant Site-to-Site VPN with Active/Standby Gateways and Load BalancingNetwork DiagramOpen →