DMVPN hub-and-spoke
The basic mGRE tunnel environment presented in the previous example is not protected by IPsec encryption, which means they are not secure and would not be suitable for a production network unless otherwise secured. DMVPN uses mGRE, NHRP, and IPsec to provide a secure hub-and-spoke tunnel environment.
The previous example shows the mGRE and NHRP configuration. This section presents the IPsec configuration required to secure the environment shown in the previous example and provide a complete DMVPN solution. For more information on configuring IPsec site-to-site environments, see Ciena Vyatta Network OS IPsec Site-to-Site VPN Configuration Guide.