TechKnowSurge
Cisco CCNA 5.5 Cisco CCNA 1.2
VideoNetworkFree

Dynamic multipoint VPN (DMVPN)

Cisco's Dynamic Multipoint VPN (DMVPN) solves the scalability and management challenges of traditional site-to-site VPN deployments by enabling hub-and-spoke connectivity with dynamic direct spoke-to-spoke tunnels. A single DMVPN replaces the complex full-mesh configurations that would otherwise require dozens of individually managed VPN connections.

Complete this video to capture a CTF flag worth 1 point.

About this video

Traditional site-to-site VPN architectures present a significant scalability challenge as enterprise networks grow. When a headquarters location needs to connect multiple satellite sites, each link requires a separately configured VPN tunnel. A hub-and-spoke model with seven remote sites demands seven tunnels, but it forces all inter-site traffic through headquarters, introducing latency and creating a single point of failure. Moving to a full mesh eliminates that bottleneck but multiplies complexity — seven sites alone require 28 individual VPN connections to achieve direct connectivity between every pair of locations. Cisco's Dynamic Multipoint VPN (DMVPN) resolves both problems within a single, unified framework. The headquarters router operates as the DMVPN hub, and each remote site is configured as a spoke. Every spoke establishes a persistent VPN connection to the hub, providing the baseline connectivity and a registration point for network-wide reachability information. The key advantage is what happens when spoke-to-spoke communication is needed: rather than routing traffic through headquarters, the initiating spoke queries the hub for the target spoke's connection details and then builds a direct, dynamic tunnel on demand. This on-demand tunneling means direct paths exist between any two sites without pre-configuring or statically managing those connections. The result is a network that delivers the performance and resilience of a full mesh while requiring only a fraction of the administrative effort. The entire topology is managed as a single DMVPN, regardless of how many spokes are added over time. New sites can join the DMVPN by connecting to the hub, automatically becoming reachable by all other spokes without any reconfiguration across the network. This combination of simplified management, dynamic path optimization, and built-in scalability makes DMVPN a foundational technology in Cisco-based enterprise WAN design.

What you'll learn

What's covered

Cisco DMVPN

Aligned to

Cisco CCNA
5.5 Describe IPsec remote access and site-to-site VPNs
1.2 Describe characteristics of network topology architectures

Key terms

Virtual Private Network
VPN
A technology that creates a secure, encrypted tunnel over a public network to protect data in transit.
Dynamic Multipoint VPN
DMVPN
A Cisco proprietary protocol that uses a hub-and-spoke architecture to enable scalable VPN connectivity, allowing spokes to dynamically establish direct tunnels with one another without routing all traffic through the hub.
Encapsulation
The process of wrapping data with protocol headers as it passes down the layers of the OSI model.
Hub-and-Spoke
A network topology where a central hub site connects to multiple remote spoke sites, with spokes communicating through or via the hub.
Full Mesh
A network topology where every site has a direct connection to every other site, requiring a large number of individual links or tunnels.

Transcript

Cisco has this proprietary protocol called Dynamic Multipoint VPN, or dynamic multipoint virtual private network — DMVPN. It's a really cool protocol that allows us to interconnect many of our different sites together in a very dynamic way.

The Scaling Problem with Standard VPNs

Let's look at a scaling problem with just a standard VPN. We have a headquarters here, and let's say we want to interconnect that with all of our satellite campuses. In total we have seven different satellite campuses here, so we want to extend a VPN to each one of those sites. Not too big of a deal — here we go from headquarters to site one, and then again to site two. We create a VPN between each one of these sites, so we're going to create seven different VPNs here to create this connectivity.

Now this causes a couple of problems. Number one, let's say we want satellite 7 to communicate with satellite 2. Right now it has to go through the headquarters to satellite 2, so this causes delay problems because it's got to go all through the headquarter office. As well as, if the headquarter office goes down, it creates connectivity issues between all of the different sites. It's not self-healing.

So this is problematic with just a standard VPN. And then what we do is we want to create a mesh network, so we start connecting site one to all of the sites as well, and then site two to all of the sites, and then site three to all of the sites. What happens is we end up with a lot of VPN connections — in fact 28 in total, 28 different VPNs. So it's a lot to manage.

Hub and Spoke with DMVPN

This is where a dynamic multipoint VPN, or DMVPN, can come in handy. Here we have the headquarter office. What we're going to do is turn that into a hub, and then each one of these will be a spoke to the hub. So we'll turn each one of these satellite campuses into a spoke, and we'll program the equipment on there to be part of this DMVPN. What will happen is each one of these sites will make a connection into the headquarter office and create a VPN connection here.

Now the beauty in all of this is not only that, but if site 6 wants to talk to site two, then it can start figuring out these settings from the hub on how to get to site number two, and then we'll communicate to site two directly. Therefore it doesn't have to send all of the traffic through headquarters — now it can go out and speak directly to the site two.

So it really creates this more dynamic setup of communication between all of these. It creates a full mesh between all of these. So instead of having 28 VPNs, now you could just have one DMVPN.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →