{"id":267944,"date":"2015-11-11T11:10:03","date_gmt":"2015-11-11T08:10:03","guid":{"rendered":"http:\/\/savepearlharbor.com\/?p=267944"},"modified":"-0001-11-30T00:00:00","modified_gmt":"-0001-11-29T21:00:00","slug":"","status":"publish","type":"post","link":"https:\/\/savepearlharbor.com\/?p=267944","title":{"rendered":"\u0414\u0432\u0430 \u043f\u0440\u043e\u0432\u0430\u0439\u0434\u0435\u0440\u0430 \u0438\u043d\u0442\u0435\u0440\u043d\u0435\u0442 \u043d\u0430 \u0441\u0445\u0435\u043c\u0435 DMVPN \u2014 \u0440\u0430\u0437\u0432\u0435\u0434\u0435\u043d\u0438\u0435 \u043f\u043e \u0440\u0430\u0437\u043d\u044b\u043c VRF \u043d\u0430 Spoke-\u0430\u0445"},"content":{"rendered":"<p>       \u0425\u043e\u0447\u0443 \u043e\u043f\u0438\u0441\u0430\u0442\u044c \u0441\u0445\u0435\u043c\u0443 \u0441 DMVPN, \u043f\u043e\u0441\u0442\u0440\u043e\u0435\u043d\u043d\u0443\u044e \u0443 \u043d\u0430\u0441 \u0432 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0443\u044e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u043d\u0435\u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u043d\u043e\u0435 \u0447\u0438\u0441\u043b\u043e \u043a\u0430\u043d\u0430\u043b\u043e\u0432 \u0441\u0432\u044f\u0437\u0438 \u043d\u0430 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0439 \u0442\u043e\u0447\u043a\u0435 \u0447\u0435\u0440\u0435\u0437 Public Internet \u043d\u0430\u0440\u044f\u0434\u0443 \u0441 \u043a\u0430\u043d\u0430\u043b\u043e\u043c IPVPN \u043e\u0442 \u043e\u0434\u043d\u043e\u0433\u043e \u0438\u0437 \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u0438\u0445 \u043f\u0440\u043e\u0432\u0430\u0439\u0434\u0435\u0440\u043e\u0432.<\/p>\n<p>  \u0427\u0442\u043e \u0435\u0441\u0442\u044c: \u043f\u043e\u0441\u0442\u0440\u043e\u0435\u043d\u043d\u0430\u044f \u0441\u0445\u0435\u043c\u0430 DMVPN \u0441 (\u0432 \u043e\u0441\u043d\u043e\u0432\u043d\u043e\u043c) \u0434\u0432\u0443\u043c\u044f \u043a\u0430\u043d\u0430\u043b\u0430\u043c\u0438 \u0441\u0432\u044f\u0437\u0438. \u041e\u0441\u043d\u043e\u0432\u043d\u043e\u0439 \u2014 IPVPN (\u0441 \u0433\u0430\u0440\u0430\u043d\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0439 \u0441\u043a\u043e\u0440\u043e\u0441\u0442\u044c\u044e) \u043e\u0442 \u043e\u0434\u043d\u043e\u0433\u043e \u0438\u0437 \u043f\u0440\u043e\u0432\u0430\u0439\u0434\u0435\u0440\u043e\u0432, \u0440\u0435\u0437\u0435\u0440\u0432\u043d\u044b\u0439 \u2014 Public Internet (\u043b\u044e\u0431\u043e\u0439, \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e \u0434\u0430\u0436\u0435 3G\\LTE \u0440\u043e\u0443\u0442\u0435\u0440) \u043e\u0442 \u0434\u0440\u0443\u0433\u043e\u0433\u043e \u043f\u0440\u043e\u0432\u0430\u0439\u0434\u0435\u0440\u0430.<\/p>\n<p>  \u0421\u0445\u0435\u043c\u0430 \u0442\u043e\u0433\u043e, \u0447\u0442\u043e \u0431\u044b\u043b\u043e:<\/p>\n<p>  <img decoding=\"async\" src=\"https:\/\/habrastorage.org\/files\/472\/bbd\/edc\/472bbdedc24a4a9d9ea813174c036c1d.jpg\" alt=\"image\"\/><br \/>  <a name=\"habracut\"><\/a><br \/>  \u0417\u0430\u0434\u0430\u0447\u0430: \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0438\u0442\u044c \u0435\u0449\u0451 \u043e\u0434\u0438\u043d \u0440\u0435\u0437\u0435\u0440\u0432\u043d\u044b\u0439 \u043a\u0430\u043d\u0430\u043b \u0447\u0435\u0440\u0435\u0437 \u0441\u0442\u043e\u0440\u043e\u043d\u043d\u0435\u0433\u043e \u043f\u0440\u043e\u0432\u0430\u0439\u0434\u0435\u0440\u0430 \u0418\u043d\u0442\u0435\u0440\u043d\u0435\u0442.<\/p>\n<p>  \u041d\u0430\u0447\u043d\u0451\u043c \u0441 \u043a\u043e\u043d\u0444\u0438\u0433\u0430 \u0446\u0435\u043d\u0442\u0440\u0430\u043b\u044c\u043d\u044b\u0445 \u0445\u0430\u0431\u043e\u0432. \u0415\u0441\u0442\u044c \u0442\u0443\u043d\u043d\u0435\u043b\u044c\u043d\u044b\u0439 \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441:<\/p>\n<pre><code>interface Tunnel0  description ==== HUB for DMVPN (INET) ====  ip address XXX.XXX.11.XXX 255.255.255.0  no ip redirects  ip mtu 1400  ip pim nbma-mode  ip nhrp authentication XYZXYZ  ip nhrp map multicast dynamic \/\/ \u0434\u043e\u043b\u0436\u043d\u044b \u0431\u044b\u0442\u044c \u0440\u0430\u0437\u043d\u044b\u0435  ip nhrp network-id &lt;b&gt;11111&lt;\/b&gt;  ip nhrp holdtime 600  ip nhrp shortcut  ip nhrp redirect  ip summary-address eigrp 77 10.0.0.0 255.0.0.0  ip summary-address eigrp 77 172.16.0.0 255.240.0.0  ip summary-address eigrp 77 192.168.0.0 255.255.0.0  ip tcp adjust-mss 1320  load-interval 30  &lt;b&gt;delay 10000&lt;\/b&gt;  tunnel source &lt;Internet Interface&gt;  tunnel mode gre multipoint  tunnel key 999999  tunnel vrf INET \/\/ \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440 shared \u043e\u0431\u044f\u0437\u0430\u0442\u0435\u043b\u0435\u043d  tunnel protection ipsec profile DMVPN_INET &lt;b&gt;shared&lt;\/b&gt; <\/code><\/pre>\n<p>  \u0421\u043e\u0437\u0434\u0430\u0451\u043c \u0435\u0449\u0451 \u043e\u0434\u0438\u043d \u0442\u0443\u043d\u043d\u0435\u043b\u044c\u043d\u044b\u0439 \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441 \u0441 \u0434\u0440\u0443\u0433\u043e\u0439 \u0430\u0434\u0440\u0435\u0441\u0430\u0446\u0438\u0435\u0439, \u0447\u0442\u043e\u0431\u044b \u043d\u0435 \u043f\u0435\u0440\u0435\u0441\u0435\u043a\u0430\u043b\u0438\u0441\u044c:<\/p>\n<pre><code>interface Tunnel3  description ==== HUB for DMVPN (INET2) ====  ip address \u0425\u0425\u0425.\u0425\u0425\u0425.12.\u0425\u0425\u0425 255.255.255.0  no ip redirects  ip mtu 1400  ip pim nbma-mode  ip nhrp authentication XYZXYZ  ip nhrp map multicast dynamic \/\/ \u0434\u043e\u043b\u0436\u043d\u044b \u0431\u044b\u0442\u044c \u0440\u0430\u0437\u043d\u044b\u0435  ip nhrp network-id &lt;b&gt;22222&lt;\/b&gt;   ip nhrp holdtime 600  ip nhrp shortcut  ip nhrp redirect  ip summary-address eigrp 77 10.0.0.0 255.0.0.0  ip summary-address eigrp 77 172.16.0.0 255.240.0.0  ip summary-address eigrp 77 192.168.0.0 255.255.0.0  ip tcp adjust-mss 1320  load-interval 30 &lt;b&gt; delay 1000&lt;\/b&gt;  tunnel source Port-channel1.501  tunnel mode gre multipoint  tunnel key 888888  tunnel vrf INET \/\/ \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440 shared \u043e\u0431\u044f\u0437\u0430\u0442\u0435\u043b\u0435\u043d  tunnel protection ipsec profile DMVPN_INET &lt;b&gt;shared&lt;\/b&gt; <\/code><\/pre>\n<p>  \u041d\u0430 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0439 \u0442\u043e\u0447\u043a\u0435 \u0434\u0432\u0430 \u0440\u0430\u0437\u043d\u044b\u0445 \u043a\u0430\u043d\u0430\u043b\u0430 Public Internet \u0440\u0430\u0437\u0432\u0435\u0434\u0435\u043d\u044b \u043f\u043e \u0434\u0432\u0443\u043c \u0440\u0430\u0437\u043d\u044b\u043c VRF \u0438 \u043f\u0440\u043e\u043f\u0438\u0441\u0430\u043d\u044b Static Route \u0432 \u043a\u0430\u0436\u0434\u043e\u043c VRF:<\/p>\n<pre><code>ip vrf INET1  rd 10:10 ! ip vrf INET2  rd 100:100   crypto ipsec profile DMVPN  set transform-set AES256-SHA   set pfs group2 !          crypto ipsec profile DMVPN2  set transform-set AES256-SHA   set pfs group2  interface Tunnel0  ip address XXX.XXX.11.XXX 255.255.255.0  no ip redirects  ip mtu 1400  ip hello-interval eigrp 77 4  ip flow ingress  ip flow egress  ip nhrp network-id 11111  ip nhrp holdtime 300  ip nhrp shortcut  ip nhrp redirect  ip tcp adjust-mss 1360  load-interval 30  &lt;b&gt;delay 10 &lt;\/b&gt;  if-state nhrp  tunnel source &lt;Internet Interface1&gt;  tunnel mode gre multipoint  tunnel key 999999  tunnel vrf INET1  tunnel protection ipsec profile DMVPN !          interface Tunnel1  ip address XXX.XXX.12.XXX 255.255.255.0  no ip redirects  ip mtu 1400  ip hello-interval eigrp 77 4  ip nhrp authentication XYZXYZ  ip nhrp network-id 22222  ip nhrp holdtime 300  ip nhrp shortcut  ip nhrp redirect  ip tcp adjust-mss 1320  load-interval 30 &lt;b&gt; delay 5000&lt;\/b&gt;  if-state nhrp  tunnel source &lt;Internet Interface2&gt;  tunnel mode gre multipoint  tunnel key 888888  tunnel vrf INET2  tunnel protection ipsec profile DMVPN2  router eigrp 77  network XXX.XXX.11.XXX  network XXX.XXX.12.XXX exit   ip route vrf INET1 0.0.0.0 0.0.0.0 &lt;Internet Interface1&gt; &lt;GW Address1&gt; name INET1 ip route vrf INET2 0.0.0.0 0.0.0.0 &lt;Internet Interface2&gt; &lt;GW Address2&gt; name INET2 <\/code><\/pre>\n<p>  \u0412\u044b\u0431\u043e\u0440 \u0442\u043e\u0433\u043e \u0438\u043b\u0438 \u0438\u043d\u043e\u0433\u043e \u043a\u0430\u043d\u0430\u043b\u0430 \u0434\u043b\u044f \u043f\u0435\u0440\u0435\u0434\u0430\u0447\u0438 \u0434\u0430\u043d\u043d\u044b\u0445 \u0440\u0435\u0433\u0443\u043b\u0438\u0440\u0443\u0435\u0442\u0441\u044f \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440\u0430\u043c\u0438 Bandwidth \u0438 Delay \u0432 <b>interface Tunnel \u0425<\/b>.<\/p>\n<p>  \u0427\u0442\u043e \u0441\u0442\u0430\u043b\u043e:<br \/>  <img decoding=\"async\" src=\"https:\/\/habrastorage.org\/files\/51e\/bd8\/e44\/51ebd8e44edc4eb29dd3fb04c769d03c.jpg\" alt=\"image\"\/><\/p>\n<p>  \u0422\u0430\u043a\u0438\u043c \u043e\u0431\u0440\u0430\u0437\u043e\u043c \u043c\u044b \u043c\u043e\u0436\u0435\u043c \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0438\u0442\u044c \u043d\u0435\u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u043d\u043e\u0435 \u0447\u0438\u0441\u043b\u043e \u043a\u0430\u043d\u0430\u043b\u043e\u0432 \u0434\u043b\u044f \u0440\u0435\u0437\u0435\u0440\u0432\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0442\u043e\u0447\u043a\u0438.<\/p>\n<p>  \u042d\u0442\u043e \u043a\u0440\u0430\u0439\u043d\u0435 \u0443\u0434\u043e\u0431\u043d\u043e \u0434\u043b\u044f \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u0440\u0435\u0437\u0435\u0440\u0432\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u043f\u0440\u043e\u043f\u0430\u0434\u0430\u043d\u0438\u044f \u0441\u0432\u044f\u0437\u0438 \u043f\u043e \u043b\u044e\u0431\u043e\u043c\u0443 \u0438\u0437 \u0447\u0438\u0441\u043b\u0430 \u043a\u0430\u043d\u0430\u043b\u043e\u0432 \u0438 \u043e\u0447\u0435\u043d\u044c \u0443\u0434\u043e\u0431\u043d\u043e\\\u0431\u044b\u0441\u0442\u0440\u043e \u0434\u043b\u044f \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u043d\u043e\u0432\u043e\u0433\u043e \u043a\u0430\u043d\u0430\u043b\u0430, \u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, \u0447\u0435\u0440\u0435\u0437 \u043c\u043e\u0431\u0438\u043b\u044c\u043d\u044b\u0439 \u0440\u043e\u0443\u0442\u0435\u0440 3G\\LTE.       <\/p>\n<div class=\"clear\"><\/div>\n<p> \u0441\u0441\u044b\u043b\u043a\u0430 \u043d\u0430 \u043e\u0440\u0438\u0433\u0438\u043d\u0430\u043b \u0441\u0442\u0430\u0442\u044c\u0438 <a href=\"http:\/\/habrahabr.ru\/post\/270629\/\"> http:\/\/habrahabr.ru\/post\/270629\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>       \u0425\u043e\u0447\u0443 \u043e\u043f\u0438\u0441\u0430\u0442\u044c \u0441\u0445\u0435\u043c\u0443 \u0441 DMVPN, \u043f\u043e\u0441\u0442\u0440\u043e\u0435\u043d\u043d\u0443\u044e \u0443 \u043d\u0430\u0441 \u0432 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0443\u044e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u043d\u0435\u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u043d\u043e\u0435 \u0447\u0438\u0441\u043b\u043e \u043a\u0430\u043d\u0430\u043b\u043e\u0432 \u0441\u0432\u044f\u0437\u0438 \u043d\u0430 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0439 \u0442\u043e\u0447\u043a\u0435 \u0447\u0435\u0440\u0435\u0437 Public Internet \u043d\u0430\u0440\u044f\u0434\u0443 \u0441 \u043a\u0430\u043d\u0430\u043b\u043e\u043c IPVPN \u043e\u0442 \u043e\u0434\u043d\u043e\u0433\u043e \u0438\u0437 \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u0438\u0445 \u043f\u0440\u043e\u0432\u0430\u0439\u0434\u0435\u0440\u043e\u0432.<\/p>\n<p>  \u0427\u0442\u043e \u0435\u0441\u0442\u044c: \u043f\u043e\u0441\u0442\u0440\u043e\u0435\u043d\u043d\u0430\u044f \u0441\u0445\u0435\u043c\u0430 DMVPN \u0441 (\u0432 \u043e\u0441\u043d\u043e\u0432\u043d\u043e\u043c) \u0434\u0432\u0443\u043c\u044f \u043a\u0430\u043d\u0430\u043b\u0430\u043c\u0438 \u0441\u0432\u044f\u0437\u0438. \u041e\u0441\u043d\u043e\u0432\u043d\u043e\u0439 \u2014 IPVPN (\u0441 \u0433\u0430\u0440\u0430\u043d\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0439 \u0441\u043a\u043e\u0440\u043e\u0441\u0442\u044c\u044e) \u043e\u0442 \u043e\u0434\u043d\u043e\u0433\u043e \u0438\u0437 \u043f\u0440\u043e\u0432\u0430\u0439\u0434\u0435\u0440\u043e\u0432, \u0440\u0435\u0437\u0435\u0440\u0432\u043d\u044b\u0439 \u2014 Public Internet (\u043b\u044e\u0431\u043e\u0439, \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e \u0434\u0430\u0436\u0435 3G\\LTE \u0440\u043e\u0443\u0442\u0435\u0440) \u043e\u0442 \u0434\u0440\u0443\u0433\u043e\u0433\u043e \u043f\u0440\u043e\u0432\u0430\u0439\u0434\u0435\u0440\u0430.<\/p>\n<p>  \u0421\u0445\u0435\u043c\u0430 \u0442\u043e\u0433\u043e, \u0447\u0442\u043e \u0431\u044b\u043b\u043e:<\/p>\n<p>  <img decoding=\"async\" src=\"https:\/\/habrastorage.org\/files\/472\/bbd\/edc\/472bbdedc24a4a9d9ea813174c036c1d.jpg\" alt=\"image\"\/>  <\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-267944","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/267944","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=267944"}],"version-history":[{"count":0,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/267944\/revisions"}],"wp:attachment":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=267944"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=267944"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=267944"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}