Siemens SCALANCE W1750D UI Configuration Manual page 532

Table of Contents

Advertisement

AP-VPN Deployment Scenarios
35.1 Scenario 1 - IPsec: Single Datacenter Deployment with No Redundancy
AP Configuration
The following table provides information on the configuration steps performed through the
CLI with example values. For information on the UI procedures, see the topics referenced in
the
Table 35- 1
AP Configuration for Scenario 1—IPsec: Single Datacenter Deployment with No Redundancy
Configuration Steps
1. Configure the primary host for VPN
with the Public VRRP IP address of
the controller.
2. Configure a routing profile to tunnel
all 10.0.0.0/8 subnet traffic to control-
ler.
3. Configure Enterprise DNS for split
DNS. The example in the next column
uses a specific enterprise domain to
only tunnel all DNS queries matching
that domain to corporate.
4. Configure Centralized, L2 and
Distributed, L3 with
VLAN 20 and VLAN 30, respectively.
532
UI Procedure
column.
CLI Commands
(scalance)(config)# vpn primary <public
VRRP IP of controller>
(scalance)(config)# routing-profile (scal-
ance)(routing-profile)# route 10.0.0.0
255.0.0.0 <public VRRP IP of controller>
(scalance)(config)# internal-domains
(scalance)(domains)# domain-name corpdo-
main.com
Centralized, L2 profile
(scalance)(config)# ip dhcp l2-dhcp
(scalance)(DHCP Profile "l2-dhcp")# server-
type Centralized,L2
(scalance)(DHCP Profile "l2-dhcp")# server-vlan 20
Distributed, L3 profile
(scalance)(config)# ip dhcp l3-dhcp
(scalance)(DHCP Profile "l3-dhcp")# server-
type Distributed,L3
(scalance)(DHCP Profile "l3-dhcp")# server-
vlan 30
(scalance)(DHCP Profile "l3-dhcp")# ip-
range
10.30.0.0 10.30.255.255
(scalance)(DHCP Profile "l3-dhcp")# dns-
server
10.1.1.50,10.1.1.30
(scalance)(DHCP Profile "l3-dhcp")# domain-
name
corpdomain.com
(scalance)(DHCP Profile "l3-dhcp")# client-
count
200
NOTE: The IP range configuration on each branch
will be the same. Each AP will derive a smaller sub-
net based on the client count scope using the
Branch ID (BID) allocated by controller.
UI Procedure
See Configuring an IPsec
Tunnel
See Configuring Routing
Profiles
See Configuring Enterprise
Domains
See Configuring Central-
ized DHCP Scopes
and Configuring Distributed
DHCP Scopes
Configuration Manual, 02/2018, C79000-G8976-C451-02
SCALANCE W1750D UI

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents