Changes

m
no edit summary
Line 217: Line 217:  
- Set Network to 192.168.10.0/24
 
- Set Network to 192.168.10.0/24
   −
<br>[[File:DMVPN HUB Phase3 spoke example5.png|border|class=tlt-border]]
+
<br>[[File:Spoke bgp.png|alt=|border]]
 
----
 
----
   Line 229: Line 229:  
- Leave everything else as default value
 
- Leave everything else as default value
   −
<br>[[File:DMVPN HUB Phase3 spoke example6.png|border|class=tlt-border]]
+
<br>[[File:Spoke bgp peer.png|alt=|border]]
    
===Spoke 2 configuration: DMVPN===
 
===Spoke 2 configuration: DMVPN===
Line 235: Line 235:  
Navigate to the <b>Services → VPN → DMVPN</b> page and follow the instructions provided below.
 
Navigate to the <b>Services → VPN → DMVPN</b> page and follow the instructions provided below.
   −
<b>Step 1</b>: create a new DMVPN instance:
+
<b>Step 1</b>: create a new DMVPN instance:  
   −
- Add HUB address  (this is the public IP address of the previously configured hub device)
+
1. Add HUB address  (this is the public IP address of the previously configured hub device)
   −
- Select Tunnel source (this is the egress interface, which will be able to reach the hub device's public IP address over the internet)
+
2. Select Tunnel source (this is the egress interface, which will be able to reach the hub device's public IP address over the internet)
   −
- Add Local GRE interface IP address  (this is the GRE IP address of "Spoke 2". It should be unique in the entire VPN network)  
+
3.  Add Local GRE interface IP address  (this is the GRE IP address of "Spoke 2". It should be unique in the entire VPN network)  
   −
- Add Remote GRE interface IP address (this is the GRE IP address of the previously configured hub device)
+
4.  Add Remote GRE interface IP address (this is the GRE IP address of the previously configured hub device)
   −
- Set GRE MTU to 1420  (this value should be set to the same value that was configured on the hub device. In our case, it is "1420")
+
5.  Set GRE MTU to 1420  (this value should be set to the same value that was configured on the hub device. In our case, it is "1420")
   −
- Set Local identifier (For setups behind NAT), Remote identifier as %any and input the same Pre-shared key (This will determine how other devices will be identified for authentication)
+
6. Set Local identifier (For setups behind NAT), Remote identifier as %any and input the same Pre-shared key (This will determine how other devices will be identified for authentication)
   −
<br>[[File:DMVPN phase3 example5.png|alt=|border]]
+
<br>[[File:Spoke2 dmvpn.png|alt=|border]]
 
----
 
----
   Line 261: Line 261:  
- Select DH group MODP3072
 
- Select DH group MODP3072
   −
<br>[[File:DMVPN phase3 example2.png|alt=|border]]
+
<br>[[File:Hub phase1.png|alt=spoke phase1|border]]
 
----
 
----
 
<b>Step 3</b>: configure DMVPN Phase 2 parameters:
 
<b>Step 3</b>: configure DMVPN Phase 2 parameters:
Line 271: Line 271:  
- Select PFS group MODP3072
 
- Select PFS group MODP3072
   −
<br>[[File:DMVPN phase3 example3.png|alt=|border]]
+
<br>[[File:Hub phase2 fix.png|alt=spoke phase2|border]]
 
----
 
----
   Line 281: Line 281:  
- Leave everything by default
 
- Leave everything by default
   −
<br>[[File:DMVPN HUB Phase3 spoke2 example4.png|border|class=tlt-border]]
+
<br>[[File:Redirect.png|alt=Redirect|border]]
 
----
 
----
 
<b>Step 5</b>: save changes
 
<b>Step 5</b>: save changes
Line 297: Line 297:  
- Set Network to 192.168.20.0/24
 
- Set Network to 192.168.20.0/24
   −
<br>[[File:DMVPN HUB Phase3 spoke2 example5.png|border|class=tlt-border]]
+
<br>[[File:Spoke2 bgp peer.png|alt=|border]]
 
----
 
----
   Line 309: Line 309:  
- Leave everything else as default value
 
- Leave everything else as default value
   −
<br>[[File:DMVPN HUB Phase3 spoke2 example6.png|border|class=tlt-border]]
+
<br>[[File:Spoke bgp peer.png|alt=Spoke bgp peer|border]]
    
----
 
----
Line 317: Line 317:  
For HUB in Network > Firewall GRE zone change from REJECT to ACCEPT on FORWARD.
 
For HUB in Network > Firewall GRE zone change from REJECT to ACCEPT on FORWARD.
   −
[[File:DMVPN HUB Phase3 example Firewall.png|border|class=tlt-border]]
+
[[File:Firewall.png|alt=|border]]
    
===Testing configuration===
 
===Testing configuration===

Navigation menu