Aruba IAP-335 User Manual page 402

Instant software
Hide thumbs Also See for IAP-335:
Table of Contents

Advertisement

10.2.2.0/24 is a branch-owned subnet, which needs to override global routing profile
l
199.127.104.32 is used an example IP address of the AirWave server in the Internet
l
IAP Configuration
The following table provides information on the configuration steps performed through the CLI with example
values. For information on the UI procedures, see the topics referenced in the UI Procedure column.
Table 85: IAP Configuration for Scenario 2—IPsec: Single Datacenter with Multiple controllers for Redundancy
Configuration Steps
1. Configure the primary
host for VPN with the
Public VRRP IP address of
the controller.
2. Configure routing
profiles to tunnel traffic
through IPsec.
3. Define routing profile
exception RADIUS server
and AirWave IPs, since
the design requirement
for this solution requires
local RADIUS
authentication, even
though the IP matches
the routing profile
destination.
4. Configure Enterprise
DNS. The configuration
example in the next
column tunnels all DNS
queries to the original
DNS server of clients
without proxying on IAP.
5. Configure Centralized, L2
and Distributed, L3 with
VLAN 20 and VLAN 30,
respectively.
Aruba Instant 6.5.0.0-4.3.0.0 | User Guide
CLI Commands
(Instant AP)(config)# vpn primary <public VRRP IP of
controller>
(Instant AP)(config)# routing-profile
(Instant AP)(routing-profile)# route 0.0.0.0 0.0.0.0
<public VRRP IP of controller>
(Instant AP)(config)# routing-profile
(Instant AP)(routing-profile)# route 10.2.2.1
255.255.255.255 0.0.0.0
(Instant AP)(routing-profile)# route 10.2.2.2
255.255.255.255 0.0.0.0
(Instant AP)(routing-profile)# route 199.127.104.32
255.255.255.255 0.0.0.0
(Instant AP)(config)# internal-domains
(Instant AP)(domains)# domain-name *
Centralized, L2 profile
(Instant AP)(config)# ip dhcp l2-dhcp
(Instant AP)(DHCP Profile "l2-dhcp")# server-type
Centralized,L2
(Instant AP)(DHCP Profile "l2-dhcp")# server-vlan 20
Distributed, L3 profile
(Instant AP)(config)# ip dhcp l3-dhcp
(Instant AP)(DHCP Profile "l3-dhcp")# server-type
Distributed,L3
(Instant AP)(DHCP Profile "l3-dhcp")# server-vlan 30
(Instant AP)(DHCP Profile "l3-dhcp")# ip-range
10.30.0.0 10.30.255.255
(Instant AP)(DHCP Profile "l3-dhcp")# dns-server
10.1.1.50,10.1.1.30
(Instant AP)(DHCP Profile "l3-dhcp")# domain-name
corpdomain.com
UI Procedure
See
Configuring an
IPsec Tunnel
See
Configuring
Routing
Profiles
See
Configuring
Routing
Profiles
See
Configuring
Enterprise
Domains
See
Configuring
Centralized
DHCP Scopes
and
Configuring
Distributed
DHCP Scopes
IAP-VPN Deployment Scenarios |
402

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents