INS_RL1000GW_REV– 15 Jul 2016 PAGE 134
INSTALLATION AND OPERATION MANUAL
RL1000GW
TECH SUPPORT: 1.888.678.9427
Layer 3 DM-VPN
The DM-VPN mGRE mode is routing based and supports more complex networking and
protection, providing higher scalability.
Topologies supported and guidelines
1. Multiple Hubs vs Multiple Spokes
2. Multiple Clouds
3. Multiple tunnels allowed at the hub.
4. Multiple tunnels allowed at each spoke towards different Hubs or towards the same hub via
different clouds.
5. Supports static routing and OSPF
6. Layer 3 protection
7. The hub is recommended to be connected to the network using one of its Ethernet ports. A
cellular uplink at the hub is not recommended as an aggregation interface to multiple VPNs.
8. A Spoke may have DM-VPN set over its cellular interface (at supported hardware) or Ethernet
ports.
9. The hub listens for incoming NHRP requests from the spokes to initiate VPN. As such, it must
hold a static IP address which is routable over the network.
Main advantages
1. Robust and supports large scale networks
2. Encryption of traffic as a protective measure against man in the middle attacks.
3. Addition of Spokes may not require further configuration at the Hub.