Dell PowerConnect W-IAP3WN/P User Manual Page 223

  • Download
  • Add to my manuals
  • Print
  • Page
    / 377
  • Table of contents
  • TROUBLESHOOTING
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 222
Dell Networking W-Series Instant 6.4.0.2-4.1 | User Guide IAP-VPN Deployment | 223
Chapter 15
IAP-VPN Deployment
This section provides the following information:
l Understanding IAP-VPN Architecture on page 223
l Configuring W-IAP and Controller for IAP-VPN Operations on page 225
Understanding IAP-VPN Architecture
The IAP-VPN architecture includes the following two components:
l W-IAPs at branch sites
l Controller at the datacenter
The master W-IAP at the branch acts as the VPN endpoint and the controller at the datacenter acts as the VPN
concentrator. When a W-IAP is set up for VPN, it forms an IPsec tunnel to the controller to secure sensitive
corporate data. IPsec authentication and authorization between the controller and the W-IAPs is based on the RAP
whitelist configured on the controller.
Only the master AP in a W-IAP cluster forms the VPN tunnel.
From the controller perspective, the master W-IAPs that form the VPN tunnel are considered as VPN clients. The
controller terminates VPNtunnels and routes or switches VPN traffic. The W-IAP cluster creates an IPSec or GRE
VPNtunnel from the Virtual Controller to a mobility controller in a branch office. The controller only acts an IPSec or
GRE VPN end-point and it does not configure the W-IAP.
IAP-VPN Scalability Limits
The controller scalability in IAP-VPN architecture depends on factors such as IPsec tunnel limit, Branch ID limit and
datapath route table limit. The following table provides the IAP-VPN scalability information for various controller
platforms:
Platforms Branches Routes L3 Mode Users NATUsers Total L2 Users
W-3200 1000 1000
N/A N/A
64000
W-3400 2000 2000 64000
W-3600 8000 8000 64000
W-6000M3 8000 8000 64000
W-7210 8000 8000 64000
W-7220 16000 16000 128000
W-7240 32000 32000 128000
Table 42:
IAP-VPN Scalability
l BranchesThe number of IAP-VPN branches that can be terminated on a given controller platform.
l Routes—The number of L3 routes supported on the controller.
Page view 222
1 2 ... 218 219 220 221 222 223 224 225 226 227 228 ... 376 377

Comments to this Manuals

No comments