A sanitation department needs modular IKEv2 profiles that can cover both site-to-site branches and certain remote-access clients on the same crypto headend. Which approach best matches that requirement versus classic DMVPN Phase 3?
Select an answer to reveal the explanation.
Short Explanation
Classic DMVPN is great for spoke hubs that all speak NHRP. When you also need remote-access-style clients and clean IKEv2 building blocks on one headend, FlexVPN’s modular profiles are the better toolbox.
Full Explanation
FlexVPN is Cisco’s IKEv2-based VPN framework using reusable profiles, virtual-templates, and virtual-access interfaces. It is a strong fit when designs mix site-to-site and remote-access terminations or need cleaner modular crypto than mGRE/NHRP-centric DMVPN. DMVPN Phase 3 remains excellent for dynamic spoke-to-spoke overlays but is not the primary model for remote-access client aggregation. GETVPN targets group-encrypted WANs, not this mixed headend use case.