Oct 26, 2019

Each spoke registers its public IP address with the hub and queries the NHRP database for the public IP address of the destination spoke it needs to build a VPN tunnel. mGRE Tunnel Interface is used to allow a single GRE interface to support multiple IPSec tunnels and helps dramatically to simplify the complexity and size of the configuration. DMVPN HUB and Spoke Technology, NHRP, mGRE Now the originating spoke can initiate a dynamic GRE/IPsec tunnel to the target spoke (because it knows the peer address). The spoke-to-spoke tunnel is built over the mGRE interface . DMVPN Benefits. Lowers capital and operational expenses – Reduces costs in integrating voice, video with VPN security Spoke-to-Spoke VPN Policy | Fortinet Technical Discussion Apr 27, 2014

In each spoke firewall, you configure a VPN tunnel to the hub with a destination subnet mask of 255.255.0.0, indicating that all 192.168.x.x addresses can be reached through the tunnel to the hub. At the hub, we will configure separate tunnels to each spoke with destination subnet masks of 255.255.255.0.

L3 Hub-and-Spoke VPN - Technical Documentation - Support The VPN Wizard automatically suggests RT exports and imports for both the hub sites and the spoke sites in order to establish a hub-and-spoke relationship. As before, you have the option to change the RT list by editing the suggested export or import values or by using RTs from the Route Targets table (by clicking on the magnifying glass icon).

Introduction to DMVPN Spoke to Spoke Tunneling

Introduction to DMVPN Spoke to Spoke Tunneling