In this chapter, we discuss the following:
Common design strategies in SD-WAN and DMVPN deployments
How to design and deploy SD-WAN to integrate with other IBN domains
How to design and deploy DMVPN to integrate with other IBN domains
Overview
Both Cisco Software-Defined WAN (SD-WAN) and Dynamic Multi-point Virtual Private Network (DMVPN) provide the ability to abstract the WAN service provider transports from the enterprise routing environment. Additionally, both provide a means to create and extend macro- and microsegmentation, including support for Cisco TrustSec. This support allows either architecture to be utilized as part of an end-to-end security policy. Cisco SD-WAN has many advantages as an architecture over DMVPN, such as application-aware routing and built-in automation and provisioning; however, DMVPN does have its use cases. Both of these technologies fundamentally provide an efficient way of routing between the sites by providing direct site-to-site communication without the need for going through a centralized hub or a data center.