Anycast For DMVPN Hubs
Dynamic assignment of DMVPN spoke tunnel addresses isn't just a matter of convenience. It provided the foundation for a recent design which included the following fun requirements:The underlay topology in this environment1 made it safe for me to anycast the DMVPN hubs, so that's what I did. This made the "connect to the nearest hub" problem easy to solve, but introduced some new complexity.
- There are many hub sites.
- Spokes will be network-near exactly one hub site.
- Latency between hub sites is high.
- Bandwidth between hub sites is low.
- Spoke routers don't know where they are in the network.
- Spoke routers must connect only to the nearest hub.
Hub Anycast Interface
Each DMVPN router has a loopback interface with address 192.0.2.0/32 assigned to the front-door VRF. It's configured something like this:
interface loopback 192020
description DMVPN hub anycast target
ip vrf forwarding LTE_TRANSIT
ip address 192.0.2.0 255.255.255.255
The 192.0.2.0 /32 prefix was redistributed into the IP backbone. If this device were to fail, then the next-nearest instance of 192.0.2.0 would be selected by the IGP.
Spoke Configuration
Spokes look pretty much exactly like Continue reading







Decoupling like Juniper? No comparison, say Versa's founders.