Aruba IAP-335 User Manual page 411

Instant software
Hide thumbs Also See for IAP-335:
Table of Contents

Advertisement

IAP Configuration
This section provides information on configuration steps performed by using the CLI and the UI.
Table 87: IAP Configuration for Scenario—GRE: Single Datacenter Deployment with No Redundancy
Configuration Steps
1. Configure Aruba GRE or
manual GRE
Aruba GRE uses an IPsec
l
tunnel to facilitate
controller configuration
and requires VPN to be
configured. This VPN
tunnel is not used for any
client traffic.
Manual GRE uses
l
standard GRE tunnel
configuration and
requires controller
configuration to
complete the GRE tunnel.
2. Configure routing
profiles to tunnel traffic
through GRE.
3. Configure Enterprise
DNS. The example in the
next column tunnels all
DNS queries to the
client's original DNS
server without proxying
on IAP.
4. Configure Centralized, L2
DHCP profile with VLAN
20.
Aruba Instant 6.5.0.0-4.3.0.0 | User Guide
CLI Commands
Aruba GRE configuration
(Instant AP)(config)# vpn primary <controller-IP>
(Instant AP)(config)# vpn gre-outside
Manual GRE configuration
(Instant AP)(config)# gre primary <controller-IP>
(Instant AP)(config)# gre type 80
Per-AP GRE tunnel configuration
Optionally, per-AP GRE tunnel can also be enabled, which causes
each IAP to form an independent GRE tunnel to the GRE end-
point. Aruba GRE requires each IAP MAC to be present in the
controller whitelist. Manual GRE requires GRE configuration for
the IP of each IAP on the controller.
(Instant AP)(config)# gre per-ap-tunnel
NOTE: Starting with Instant 6.5.0.0-4.3.0.0, if VC IP is configured
and per-AP GRE tunnel is disabled, IAP uses VC IP as the GRE
source IP. For Manual GRE, this simplifies configuration on
controller, since only the VC IP destined GRE tunnel interface
configuration is required.
(Instant AP)(config)# routing-profile
(Instant AP)(routing-profile)# route 0.0.0.0
0.0.0.0 <IP of GRE-endpoint>
(Instant AP)(config)# internal-domains
(Instant AP)(domains)# domain-name *
Centralized, L2 DHCP profile VLAN 20
(Instant AP)(config)# ip dhcp l2-dhcp
(Instant AP)(DHCP profile "l2-dhcp")# server-type
Centralized,L2
(Instant AP)(DHCP profile "l2-dhcp")# server-vlan
20
UI Procedure
See
Configuring
Aruba GRE
Parameters
and
Configuring
Manual GRE
Parameters
See
Configuring
Routing
Profiles
See
Configuring
Enterprise
Domains
See
Configuring
Centralized
DHCP Scopes
IAP-VPN Deployment Scenarios |
411

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents