WAN Design Requirements

DMVPN

NETWORK INSIGHT · ENGINEERING GUIDE

DMVPN: Designing and Investigating Dynamic VPN Overlays

Dynamic Multipoint VPN (DMVPN) combines multipoint GRE, Next Hop Resolution Protocol (NHRP), IPsec and dynamic routing to build scalable VPN connectivity across an underlying IP network.

The engineering challenge is not simply creating a secure tunnel. A DMVPN deployment must dynamically discover remote endpoints, establish the appropriate tunnel path, maintain routing information and provide efficient communication between sites as the network grows.

This guide moves beyond configuration syntax and examines DMVPN as an operational system. You will follow the relationship between the underlay and overlay, observe how NHRP provides endpoint resolution, investigate how spoke-to-spoke connectivity develops, and correlate routing, tunnel and security evidence when troubleshooting the network.

01 · SEE DMVPN Architecture Understand the underlay, overlay, hub, spokes and core DMVPN components.
02 · OBSERVE NHRP & Tunnel Evidence Examine mappings, tunnel state, routing information and security evidence.
03 · INVESTIGATE Spoke-to-Spoke Paths Follow NHRP redirect and resolution as traffic moves toward a direct path.
04 · OPERATE Routing & Resiliency Correlate routing, IPsec and failure evidence to verify network health.
Investigation Focus
Follow the evidence

The interactive sections turn DMVPN behaviour into an engineering investigation: identify the path, inspect the evidence, determine what changed and verify the resulting network state.

Engineering Objective

By the end of the guide, you should be able to explain how DMVPN forms and optimises its overlay, identify the evidence created by NHRP and IPsec, distinguish hub-and-spoke from direct spoke-to-spoke forwarding, and use multiple observations to isolate a DMVPN failure.

The interactive sections are designed as engineering exercises rather than demonstrations. Each stage builds on the previous one so that architecture, evidence, investigation and operational verification form one continuous learning path.
ENGINEERING GUIDE · 01 — SEE

Understand the DMVPN Architecture

Start with the dependency chain. DMVPN is not a single protocol: the underlay, mGRE, NHRP, IPsec and routing functions each solve a different engineering problem. Before troubleshooting traffic, establish which layer is responsible for connectivity, discovery, security, routing and forwarding.

UNDERLAY mGRE NHRP IPsec ROUTING
ENGINEERING EVIDENCE · SECTION 01

SEE — DMVPN Architecture

Before investigating a DMVPN failure, understand how the underlay, mGRE, NHRP, IPsec and routing functions fit together to create the overlay.

DMVPN Architecture Stack
UNDERLAY
IP connectivity between the physical / NBMA endpoints
REACHABILITY
mGRE
Multipoint tunnel framework for dynamic destinations
OVERLAY
NHRP
Dynamic discovery and logical-to-NBMA mapping
CONTROL
IPsec
Encryption and protection of overlay traffic
SECURITY
ROUTING
Destination reachability and path selection
CONTROL
Underlay

The underlying IP network provides basic reachability between DMVPN routers. If the underlay cannot reach the required peer, the overlay cannot form correctly.

From Infrastructure To Application
01
UNDERLAY
IP / NBMA reachability
›
02
mGRE
Multipoint overlay
›
03
NHRP
Peer discovery
›
04
IPsec
Traffic protection
›
05
ROUTING
Path selection
›
06
APPLICATION
End-to-end traffic
DMVPN Traffic Models
PHASE 1

Hub-and-Spoke

Traffic remains logically centred on the hub. The hub provides the central connectivity point for the spokes.

PHASE 2

Spoke-to-Spoke

Spokes can dynamically establish direct connectivity when the routing and NHRP information support the destination.

PHASE 3

Hub-Initiated

The hub can participate in redirecting traffic toward a more efficient spoke-to-spoke path.

Engineering View

DMVPN should not be investigated as a single protocol. A tunnel can appear operational while NHRP mappings, IPsec security associations or routing information are incorrect.

The investigation therefore follows the dependency chain: Underlay → mGRE → NHRP → IPsec → Routing → Forwarding.

ENGINEERING QUESTIONS
Can the underlay reach the peer?
Does NHRP know where the peer is?
Are IPsec security associations present?
Is routing selecting the expected path?
Does forwarding match the design?
ENGINEERING EVIDENCE · DMVPN ARCHITECTURE

SEE — DMVPN Architecture

Interrogate the DMVPN dependency chain. Select a layer to see what it does, what evidence proves it is working, and what depends on it.
ARCHITECTURE ONLINE
DMVPN Dependency Stack
01
UNDERLAY
Physical/IP transport and NBMA reachability
REACHABLE
02
mGRE
Multipoint tunnel framework
UP
03
NHRP
Logical tunnel-to-NBMA peer mapping
MAPPED
04
IPsec
Protection of tunnel traffic
SA UP
05
ROUTING
Prefix reachability and path selection
VALID
Engineering Dependency Chain
UNDERLAY › mGRE › NHRP › IPsec › ROUTING
LAYER 01 · TRANSPORT

Underlay Reachability

The underlay provides IP reachability between the physical or NBMA endpoints. DMVPN cannot establish useful overlay behaviour if the transport network cannot reach the required peers.

Function Transport
Example 198.51.100.11
Evidence IP route / ping
Failure boundary Peer unreachable
DMVPN Operating Model
Phase 1 · Hub-and-Spoke Spokes primarily communicate through the hub.
Phase 2 · Spoke-to-Spoke Spokes can establish direct dynamic paths.
Phase 3 · Hub-Assisted Hub redirects traffic towards an optimized peer path.
Evidence Command
show ip route 198.51.100.1
Selected Layer Depends On
The underlay is the foundation. Higher DMVPN functions ultimately depend on transport reachability.
IP Reachability NBMA Transport
What This Layer Does Not Prove
A reachable underlay does not prove that the DMVPN tunnel, NHRP mappings, IPsec SAs or routing are correct.
mGRE NHRP IPsec Routing
ENGINEERING GUIDE · 02 — DISCOVER

How NHRP Builds Dynamic Peer Knowledge

Once the tunnel framework exists, DMVPN needs a way to associate logical tunnel addresses with real NBMA destinations. NHRP provides that discovery and mapping function, allowing spokes and the NHS to build the peer information required by the overlay without turning NHRP itself into the routing protocol.

REGISTRATION NHS / NHC MAPPING RESOLUTION
ENGINEERING EVIDENCE · SECTION 02

DISCOVER — NHRP and Dynamic Peer Mapping

mGRE provides the multipoint tunnel framework, but it does not tell a DMVPN router where another peer exists on the underlay. NHRP provides the discovery and mapping mechanism that connects the logical tunnel address with the peer's NBMA address.

NHRP Discovery Sequence
01
Spoke Registration
The spoke tells the NHS where it can be reached.
02
NHRP Mapping
The hub builds dynamic peer information.
03
Resolution Request
The destination peer's location is requested.
04
Resolution Reply
Logical and NBMA information is returned.
Spoke Registration
REGISTER
SPOKE 1
NHC
HUB
NHS
SPOKE 2
NHC
NHRP EVENT
The spoke registers its tunnel address and NBMA address with the NHS.
Dynamic NHRP Information

NHRP Mapping View

DEVICE ROLE TUNNEL NBMA STATE
HUB NHS 172.16.100.1 198.51.100.1 LOCAL
SPOKE 1 NHC 172.16.100.11 198.51.100.11 REGISTERED
SPOKE 2 NHC 172.16.100.12 198.51.100.12 PENDING

Engineering Interpretation

NHRP is not the routing protocol that determines which destination network should be used. Its role is to provide the information required to reach another DMVPN peer by relating a logical tunnel address to an NBMA address.

This makes NHRP an important dependency when investigating dynamically established DMVPN connectivity.

CLI EVIDENCE
show ip nhrp
show ip nhrp nhs
show dmvpn
show ip interface tunnel 0
ENGINEERING CHECKPOINT
Is the spoke registered with the correct NHS?
Does the NHRP table contain the expected NBMA mapping?
Can the discovered peer be reached across the underlay?
CORE IDEA
NHRP discovers where a DMVPN peer lives on the underlay.
Routing still determines destination reachability and path selection.
ENGINEERING EVIDENCE · NHRP DISCOVERY

DISCOVER — Dynamic Peer Mapping

Step through the NHRP control-plane sequence and watch how a DMVPN peer moves from registration to a usable logical-to-NBMA mapping.
NHRP CONTROL PLANE
Live NHRP Discovery Sequence
The hub acts as the NHS. Spokes register their tunnel/NBMA information and can subsequently resolve dynamic peer information.
SPOKE 1
NHC
172.16.100.11
198.51.100.11
HUB
NHS
172.16.100.1
198.51.100.1
SPOKE 2
NHC
172.16.100.12
198.51.100.12
INITIAL NHRP STATE
EVENT 01 · REGISTRATION
Spoke 1 sends NHRP registration information towards the NHS, advertising its logical tunnel address and NBMA address.
Control-Plane Events
01
Spoke Registration NHC registers its logical and NBMA information with the NHS.
02
NHRP Mapping The NHS records the logical-to-NBMA relationship.
03
Resolution Request A spoke requests information for a dynamic peer.
04
Resolution Reply The requested peer mapping becomes available.
NHRP Mapping Table
Node Logical NBMA State
HUB 172.16.100.1 198.51.100.1 LOCAL
SP1 172.16.100.11 198.51.100.11 REGISTERED
SP2 172.16.100.12 198.51.100.12 PENDING
Engineering Interpretation

NHRP is not a routing protocol. Its role here is to provide the information needed to map a logical DMVPN peer to its NBMA transport address.

Operational Evidence
show ip nhrp show ip nhrp nhs show dmvpn show ip interface tunnel 0
What The Mapping Tells You
Logical address → NBMA address
The mapping establishes how a DMVPN logical peer relates to its underlying transport endpoint. It does not, by itself, prove that IPsec is established or that the routing table contains the correct destination path.
ENGINEERING GUIDE · 03 — PROTECT

How IPsec Protects the DMVPN Overlay

NHRP can identify a peer, but discovery alone does not provide security. IPsec establishes the protection required for DMVPN traffic, securing the encapsulated overlay between peers. A tunnel interface being operational is therefore not sufficient evidence that encrypted traffic is successfully passing.

IKE AUTHENTICATION IPsec SA ESP ENCRYPTION
ENGINEERING EVIDENCE · SECTION 03

PROTECT — IPsec Security

NHRP can identify where a DMVPN peer exists, but discovery does not provide confidentiality or integrity. IPsec supplies the security layer that protects DMVPN traffic as it crosses the underlying network.

Security Establishment Sequence
01
IKE / Negotiation
Security parameters are negotiated between the peers.
02
Authentication
Each peer verifies the identity of the other side.
03
IPsec SA
The negotiated security association is established.
04
GRE Protection
Overlay traffic is protected before entering the underlay.
05
Protected Transport
The secured packet traverses the underlying IP network.
IKE / Security Negotiation
NEGOTIATE
DMVPN PEER A
IPsec PEER
DMVPN PEER B
IPsec PEER
UNDERLAY / NBMA NETWORK
IPSEC PROTECTED
SECURITY EVENT
The peers negotiate the parameters required to establish protected communication.
What The Router Should Show

Security Association Evidence

PEER
198.51.100.12
STATE
ESTABLISHED
PROTOCOL
ESP

Engineering Interpretation

A working tunnel interface does not by itself prove that protected traffic can pass. IPsec security associations must be established and traffic must be processed by the correct security policy.

When troubleshooting, separate the questions: Is the peer reachable? Is the security association established? Are packets actually being encrypted and decrypted?

CLI EVIDENCE
show crypto isakmp sa
show crypto ipsec sa
show crypto session
ENGINEERING EVIDENCE · IPSEC SECURITY

PROTECT — IPsec Security

Follow the security establishment process from IKE negotiation through an operational IPsec SA and protected DMVPN traffic.

SECURITY STANDBY
Live Security Path
PEER A ↔ PEER B
STAGE 1 · IKE
A
DMVPN PEER A
198.51.100.11
B
DMVPN PEER B
198.51.100.12
UNDERLAY / NBMA TRANSPORT
NBMA · 198.51.100.11 → 198.51.100.12
IKE negotiation begins The peers establish the security negotiation required before protected traffic can be exchanged.
Security Establishment
CLICK TO INSPECT
SA Telemetry
LIVE STATE
Peer
198.51.100.12
State
NEGOTIATING
Protocol
IKE
Encrypt
0 pkts
Decrypt
0 pkts
Protection
NOT ACTIVE
Selected Stage Evidence

IKE establishes the negotiation context. At this point, an operational IPsec SA has not yet been demonstrated.

R1# show crypto isakmp sa
Engineering Interpretation

A DMVPN tunnel interface being operational does not by itself prove that encrypted traffic is successfully passing between peers.

ENGINEERING PRINCIPLE: NHRP identifies the peer's NBMA information; IPsec protects the traffic. When troubleshooting, separate peer discovery, security-association establishment and actual encrypted packet counters rather than treating “tunnel up” as proof of end-to-end operation.
ENGINEERING GUIDE · 04 — ROUTE

How Routing Determines the Overlay Path

DMVPN provides the overlay connectivity, but routing protocols determine which destination prefixes are reachable and which path is preferred. EIGRP, OSPF and BGP can operate across the overlay, each applying its own path-selection logic.

EIGRP OSPF BGP BEST PATH CEF
ENGINEERING EVIDENCE · SECTION 04

ROUTE — Routing Across the DMVPN Overlay

DMVPN provides the overlay connectivity, but routing determines which destination prefixes are reachable and which path the router prefers. EIGRP, OSPF and BGP can operate across the overlay, with the routing design influencing how traffic moves between spokes and hubs.

Select A Routing Model
EIGRP
Fast convergence and native Cisco integration.
IGP
OSPF
Link-state routing across the overlay.
IGP
BGP
Policy-driven routing and path control.
EGP
Route Decision View

EIGRP Routing Model

EIGRP can exchange routes across the DMVPN overlay and is commonly used in Cisco-centric DMVPN designs. Its metrics and next-hop behaviour influence the selected path.

Metric
LOWER
Feasibility
CHECK
Next Hop
OVERLAY
Split Horizon
DESIGN
Candidate Paths
ROUTE INSTALLED
PATH A · DIRECT SPOKE
Via Tunnel0 · metric 90
→
10.40.40.0/24
Preferred path
PATH B · HUB
Via Tunnel0 · metric 120
→
10.40.40.0/24
Alternate path
PATH C · BACKUP
Via secondary path
→
10.40.40.0/24
Standby
Select a candidate path to inspect the routing decision.

Engineering Interpretation

A DMVPN tunnel being operational does not mean that the expected route will be installed. The overlay provides connectivity between routers; the routing protocol decides which prefixes are reachable and which path should be preferred.

Investigation Question

If the destination prefix exists but traffic takes the wrong path, investigate the routing information before assuming that the DMVPN tunnel itself is broken.

CLI EVIDENCE
show ip route
show ip route 10.40.40.0
show ip protocols
show ip cef 10.40.40.0

Following the Packet Through the Overlay

A DMVPN tunnel is not the packet itself. It is the transport framework that allows one router to carry an original IP packet across an underlying network. To understand forwarding behaviour, separate the inner packet from the DMVPN overlay and the underlay transport.

Consider a packet travelling from a host behind Spoke 1 to a host behind Spoke 2. The original packet might have the source 10.10.10.10 and destination 10.40.40.40. Those addresses describe the actual communication. They are not replaced simply because the packet enters the DMVPN tunnel.

Source Host → mGRE Tunnel → IPsec Protection → Underlay → Remote Peer → Destination

The Inner Packet

The original IP packet contains the addresses used by the overlay routing decision and, ultimately, the destination host. For example:

# Original IP packet
SRC       10.10.10.10
DST       10.40.40.40
PROTOCOL  IP

Spoke 1 uses its routing and forwarding information to determine that the destination prefix is reachable through the DMVPN overlay. The packet is therefore handed towards the tunnel interface rather than being forwarded directly using the physical underlay interface.

mGRE Creates the Overlay Transport

mGRE provides the multipoint tunnel framework. Instead of requiring a separate permanent tunnel interface for every possible peer, a DMVPN router can use a single multipoint GRE tunnel to support dynamically discovered peers.

The important engineering distinction is that mGRE provides the tunnel mechanism, while NHRP provides the peer discovery and logical-to-NBMA mapping information required to reach dynamic peers.

Inner

Original source and destination addresses remain associated with the actual IP communication.

Overlay

mGRE carries the original packet across the DMVPN tunnel infrastructure.

Underlay

The transport network carries the encapsulated traffic between the DMVPN peers.

IPsec Protects the Tunnel Traffic

After the tunnel traffic has been constructed, IPsec provides the security layer. Depending on the deployment, the GRE traffic is protected using IPsec security associations and ESP.

This creates an important troubleshooting boundary. A tunnel interface can appear operational while the required IPsec security association is missing or while protected traffic is not being successfully encrypted and decrypted.

Engineering Evidence

Tunnel up does not automatically mean traffic is working. Validate the tunnel, NHRP state, IPsec security associations, routing information and forwarding behaviour independently.

The Underlay Sees the Outer Transport

Once the packet has been encapsulated and protected, the underlay network forwards the resulting transport traffic. The underlay is concerned with reaching the remote DMVPN peer rather than understanding the final application destination inside the overlay.

# Example outer transport addresses
OUTER SRC  198.51.100.11
OUTER DST  198.51.100.12
PROTOCOL   IPsec / ESP

This distinction is extremely useful during troubleshooting. If the underlay cannot reach 198.51.100.12, the overlay cannot carry the packet regardless of whether the routing configuration itself is correct.

Decapsulation at the Remote Peer

At the remote DMVPN router, the process is reversed. The protected transport is received and processed by IPsec. The tunnel encapsulation is then removed, exposing the original IP packet.

The remote router can then perform normal IP forwarding towards 10.40.40.40. The final destination therefore sees the original IP communication rather than the intermediate NBMA transport addresses used by the DMVPN infrastructure.

What Each Layer Actually Knows

Overlay Routing

Determines how the destination prefix is reached through the DMVPN overlay.

IPsec

Protects the tunnel traffic and maintains the required security associations.

Underlay

Provides transport reachability between the physical/NBMA endpoints.

Engineering Principle

Follow the packet, not just the tunnel. When a DMVPN path fails, determine which layer can no longer carry the packet. A working underlay does not prove NHRP is correct. An established NHRP mapping does not prove IPsec is protecting traffic. An established IPsec SA does not prove the routing table contains the expected destination path.

Evidence to Collect

The data plane can be correlated with the control-plane state using a small set of operational commands:

# Forwarding decision
show ip cef 10.40.40.40

# Tunnel state and counters
show interfaces tunnel 0

# NHRP peer mappings
show ip nhrp

# IPsec protection and packet counters
show crypto ipsec sa

These outputs should be interpreted together. The goal is not simply to prove that individual commands return output, but to establish a continuous forwarding chain from the source host to the destination.

ENGINEERING EVIDENCE · OVERLAY ROUTING

ROUTE — Routing Across the DMVPN Overlay

Compare candidate paths and see how the routing protocol determines which overlay path becomes the forwarding decision.

ROUTE ANALYSIS READY
Candidate Route Topology
10.40.40.0/24
R1
SOURCE
10.10.10.0/24
RR
RR1
AS65001
R4
DESTINATION
10.40.40.0/24
Candidate paths discovered The same destination prefix is visible through multiple overlay paths. The routing process must select the usable best path.
Routing Protocol
SELECT MODEL
Candidate Paths
CLICK TO INSPECT
Decision Telemetry
LIVE ANALYSIS
Protocol
EIGRP
Selected
PATH A
Destination
10.40.40.0
FIB State
CANDIDATES
Routing Evidence

The routing table contains multiple candidate paths to the same destination. The selected path is the route that will be installed for forwarding.

R1# show ip route 10.40.40.0
R1# show ip cef 10.40.40.0
Engineering Interpretation

DMVPN provides the overlay connectivity. The routing protocol determines which destination prefix is reachable and which path should be preferred.

ENGINEERING PRINCIPLE: A healthy DMVPN tunnel does not automatically mean the correct route is being used. Separate overlay connectivity from route selection, then verify the installed RIB and CEF forwarding decision.
ENGINEERING GUIDE · 05 — FORWARD

FORWARD — Follow the DMVPN Data Plane

Once the overlay is built, the real engineering question is simple: how does an actual packet travel? Follow the original IP packet from the source host through the DMVPN tunnel, across the underlay, and back into the remote network. This separates the inner packet, overlay tunnel, IPsec protection, and underlay transport so failures can be isolated to the correct layer.

INNER PACKET mGRE IPsec UNDERLAY DECAPSULATION
ENGINEERING EVIDENCE · SECTION 05

FORWARD — DMVPN Data Plane & Packet Flow

Once the overlay is established and routing has selected a path, the next question is simple: what actually happens to the packet? The DMVPN data plane combines the original IP packet, the tunnel overlay, IPsec protection and the underlay transport. Understanding these layers makes it possible to identify exactly where forwarding succeeds or fails.

→
Engineering principle The original packet is not replaced by the DMVPN transport. It is encapsulated, protected and carried across the underlay, then decapsulated at the remote endpoint.
01
Source Host Original IP packet is generated.
02
Spoke Routing selects Tunnel0.
03
mGRE Overlay encapsulation is added.
04
IPsec Tunnel traffic is protected.
05
Underlay NBMA transport forwards it.
06
Remote Spoke Traffic is decapsulated.
Packet Construction

One packet, multiple forwarding views

The endpoint application creates an ordinary IP packet. The DMVPN tunnel then provides the transport framework around that packet. mGRE identifies the tunnel overlay while IPsec protects the resulting tunnel traffic before it crosses the physical network.

INNER 10.10.10.10 → 10.40.40.40
TUNNEL Spoke1 Tunnel0 → Spoke2 Tunnel0
OUTER 198.51.100.11 → 198.51.100.12
Forwarding Layers

What each layer actually sees

IP
Inner IP The original source and destination prefixes used by the overlay routing decision.
GRE
mGRE Overlay Provides the tunnel framework used to carry the original packet between DMVPN peers.
SEC
IPsec Protection Protects the tunnel traffic before it enters the physical underlay.
WAN
Underlay Forwards the transport using the outer NBMA addresses.
Remote Processing

Decapsulation restores the original forwarding context

At the remote DMVPN peer, the protected transport is processed in the reverse direction. IPsec protection is removed, the mGRE encapsulation is removed, and the original IP packet becomes available for normal forwarding toward its destination. This distinction is critical: the physical network forwards the outer transport, while the DMVPN overlay forwards the inner destination prefix.

CEF Decision

Confirm which interface and next-hop the router selected for the destination prefix.

show ip cef 10.40.40.0

Tunnel State

Confirm the tunnel interface is operational and carrying the expected traffic.

show interfaces tunnel 0

IPsec Counters

Confirm encryption and decryption counters are increasing when traffic is generated.

show crypto ipsec sa
Engineering interpretation

If the underlay is reachable but the destination cannot be forwarded, do not treat the problem as a single “DMVPN tunnel failure.” Separate the investigation into the layers: underlay transport → tunnel encapsulation → IPsec protection → overlay routing → forwarding. The point at which the packet stops progressing identifies the most useful next piece of evidence.

ENGINEERING EVIDENCE · SECTION 05

FORWARD — Follow the DMVPN Data Plane

Trace one packet from the source host to the remote destination. Select each stage to see which address, header and forwarding function is active at that point in the journey.
DATA PLANE READY
Live Packet Journey
PACKET
01
SOURCE Original IP packet
02
mGRE Overlay encapsulation
03
IPsec Protected transport
04
UNDERLAY Outer NBMA forwarding
05
DESTINATION Decapsulation + delivery
Source Host
10.10.10.10
→
Remote Host
10.40.40.40

Original IP Packet

The source creates the original IP packet. At this point there is no DMVPN tunnel header and the destination is the final host.

Stage SOURCE
Source 10.10.10.10
Destination 10.40.40.40
Forwarding HOST
Engineering Evidence
show ip cef 10.40.40.40 show interfaces tunnel 0 show crypto ipsec sa
Packet Header Inspection INNER
Inner IP
SRC 10.10.10.10
DST 10.40.40.40
DMVPN Overlay
Tunnel0
mGRE / NHRP peer
Outer Transport
NBMA 198.51.100.11
→ 198.51.100.12
STEP 01
Original Packet Host creates IP traffic.
STEP 02
mGRE Overlay encapsulation begins.
STEP 03
IPsec GRE traffic is protected.
STEP 04
Underlay Outer addresses are forwarded.
STEP 05
Decapsulation Remote peer removes tunnel layers.
RESULT
Forwarded Original packet reaches destination.
NETWORK INSIGHT · INTERACTIVE ENGINE

DMVPN — Phase 3 Explorer

Explore DMVPN Phase 3, follow the NHRP Redirect and Resolution process, and see how the resulting spoke-to-spoke path is used.
Phase 3 Network Topology
PHASE 3 · NHRP REDIRECT
PHASE 3 · NHRP REDIRECT
Spoke 1
DMVPN SPOKE
Hub
NHRP NHS
Spoke 2
DMVPN SPOKE
NHRP REDIRECT
STEP 1 / 4
Initial traffic crosses the Hub
Spoke 1 initially sends traffic toward Spoke 2 through the DMVPN hub.
Phase 3 Detail
NHRP · OPTIMIZATION
Phase 3 — NHRP Redirect
The hub can signal that traffic between two spokes can use a more direct path.
Initial Path Spoke 1 → Hub → Spoke 2
NHRP Redirect + Resolution
Direct Path Yes
NHRP Control Plane
REGISTRATION · RESOLUTION
NHRP · CONTROL PLANE
HUB
NHRP NHS
SPOKE 1
NHRP CLIENT
SPOKE 2
NHRP CLIENT
REGISTRATION
REGISTRATION
REMOTE MAPPING / RESOLUTION
Selected Object
NHRP
NHRP Control Plane
NHRP allows DMVPN spokes to register their tunnel information and discover remote spoke mappings.
Function Peer discovery
Server Hub / NHS
Security IPsec
DMVPN Packet Encapsulation
GRE · IPSEC · UNDERLAY
ORIGINAL IP PACKET
Spoke 1
SOURCE
Spoke 2
DESTINATION
Original IP Packet
Source → Destination
GRE / mGRE
Overlay tunnel encapsulation
IPsec
Authentication / encryption protection
Underlay / Transport
Physical or routed IP transport
The original packet is carried through the DMVPN overlay and protected by IPsec.
Encapsulation Detail
PACKET FLOW
Original IP Packet
The original application packet is generated by the source network before tunnel encapsulation.
Layer Payload
Technology IP
Purpose Original traffic
ENGINEERING GUIDE · 06 — INVESTIGATE

INVESTIGATE — DMVPN Failure Workflow

A DMVPN failure should be investigated as a dependency chain, not as a single tunnel problem. Work from the underlay through mGRE, NHRP, IPsec, routing and finally forwarding to isolate the first broken layer.

Underlay mGRE NHRP IPsec Routing Forwarding
ENGINEERING EVIDENCE · SECTION 06

INVESTIGATE — DMVPN Failure Workflow

Troubleshooting DMVPN becomes much easier when the investigation follows the dependency chain established throughout this guide. Instead of treating “the tunnel is down” as the diagnosis, identify the first layer that has failed and prove it with operational evidence.

!
The first failed dependency is usually more valuable than the final symptom.

A missing route may be caused by routing policy, an unresolved NHRP peer, an unavailable IPsec security association, or a broken underlay. The correct troubleshooting sequence prevents a downstream symptom from being mistaken for the root cause.

Start With the Dependency Chain

DMVPN is not a single protocol. It is a collection of functions operating together. Each layer depends on the layers beneath it, so investigation should normally move from basic transport reachability toward the final forwarding decision.

01

Underlay

Confirm that the NBMA transport addresses are reachable before investigating the overlay.

show ip route
02

mGRE

Verify that Tunnel0 is operational and that the tunnel interface has the expected state and addressing.

show interfaces tunnel 0
03

NHRP

Check whether logical tunnel peers are correctly registered and mapped to their NBMA addresses.

show ip nhrp
04

IPsec

Confirm that the required security associations exist and that protected traffic is being encrypted and decrypted.

show crypto ipsec sa
05

Routing

Determine whether the destination prefix exists and whether the expected path has been selected.

show ip route
06

Forwarding

Verify that the selected route produces the expected CEF forwarding decision and next hop.

show ip cef

Common Failure Signatures

The same user-visible symptom can originate from different layers. The objective is therefore to correlate the symptom with the control-plane and forwarding evidence underneath it.

Underlay Unreachable

The NBMA address of the remote peer cannot be reached. NHRP, IPsec and overlay routing may subsequently appear broken because their transport dependency is unavailable.

NHRP Mapping Missing

The tunnel framework may exist, but the required logical-to-NBMA peer information is absent or incomplete. Dynamic peer communication can therefore fail.

IPsec SA Missing

Peer discovery may succeed while protected traffic still fails because the required security association has not been established or is not passing traffic.

Routing Mismatch

The DMVPN overlay can be operational while the routing process selects an unexpected path, rejects a prefix, or fails to install the destination in the forwarding table.

Evidence Before Diagnosis

A strong troubleshooting process does not begin by changing configuration. First establish what the network believes is happening. Then compare that evidence with the expected dependency state.

Peer and Tunnel Evidence

Establish whether the transport, tunnel and NHRP control plane agree about the remote peer.

! Underlay
show ip route 198.51.100.12
ping 198.51.100.12

! DMVPN / NHRP
show dmvpn
show ip nhrp

Security and Routing Evidence

Once peer reachability is established, determine whether protected transport and route installation are functioning.

! IPsec
show crypto ipsec sa
show crypto session

! Routing / forwarding
show ip route 10.40.40.0
show ip cef 10.40.40.0

The Correct Troubleshooting Order

The investigation should move from the dependency that everything else requires toward the final forwarding decision. Skipping directly to routing or application symptoms can produce misleading conclusions.

UNDERLAY
›
mGRE
›
NHRP
›
IPsec
›
ROUTING
›
FORWARDING

Engineering Conclusion

A DMVPN investigation should move from reachability → discovery → security → routing → forwarding. Each layer answers a different question. Underlay evidence proves transport reachability. NHRP proves peer discovery and mapping. IPsec proves protected transport. Routing proves the destination path. CEF and forwarding evidence prove what the router will actually do with the packet.

ENGINEERING EVIDENCE · DMVPN INCIDENT LAB

INVESTIGATE — DMVPN Failure Workflow

Inject a controlled DMVPN failure, collect evidence from each dependency layer, and identify the first failed component rather than treating the final symptom as the root cause.

NO INCIDENT
Live DMVPN Incident
CONTROL PLANE + DATA PLANE
No active failure
Select a failure scenario, inject it into the topology, then investigate the dependency chain.
S1
SPOKE 1
198.51.100.11
READY
H
HUB / NHS
198.51.100.1
READY
S2
SPOKE 2
198.51.100.12
READY
FAILURE DETECTED
Engineering target: determine which dependency fails first.
Fault Injection
SELECT INCIDENT
Evidence Collection
SEQUENTIAL
1
Underlay
WAIT
2
mGRE Tunnel
WAIT
3
NHRP
WAIT
4
IPsec
WAIT
5
Routing
WAIT
6
Forwarding
WAIT
Diagnosis
ROOT CAUSE
INVESTIGATION READY

No diagnosis yet

Inject a fault and run the investigation to correlate the evidence.

R1# show dmvpn
```
☕
Support Network Insight
Help support independent engineering guides, interactive networking tools, and future learning labs.
Support Network Insight ```
Matt Conran
Latest posts by Matt Conran (see all)

Comments are closed.