Dell PowerConnect W-IAP3WN/P User Manual Page 370

  • Download
  • Add to my manuals
  • Print
  • Page
    / 377
  • Table of contents
  • TROUBLESHOOTING
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 369
Configuration Steps CLI Commands UI Procedure
1. Configure Aruba GRE or
manual GRE
l Aruba GRE uses an
IPSec tunnel to facilitate
controller configuration
and requires VPN to be
configured. This VPN
tunnel is not used for any
client traffic.
l Manual GRE uses
standard GRE tunnel
configuration and
requires controller
configuration to complete
the GRE tunnel.
Aruba GRE configuration
(ap)(config)# vpn primary <controller-IP>
(ap)(config)# vpn gre-outside
Manual GRE configuration
(ap)(config)# gre primary <controller-IP>
(ap)(config)# gre type 80
Per-AP GRE tunnel configuration
Optionally, per-AP GRE tunnel can also be enabled, which causes
each W-IAP to form an independent GRE tunnel to the GRE end-
point. This requires each W-IAP MAC to be present in the controller
whitelist if Aruba GRE is used, or GRE configuration for the IP of the
each W-IAP on the controller for Manual GRE.
(ap)(config)# gre per-ap-tunnel
NOTE: Starting with 6.4.0.2-4.1, if Virtual Controller IP is configured
and per-AP GRE tunnel is disabled, W-IAP uses Virtual Controller
IP as the GRE source IP. For Manual GRE, this simplifies
configuration on controller, since only the Virtual Controller IP
destined GRE tunnel interface configuration is required.
See Enabling
Automatic
Configuration
of GRETunnel
and Manually
Configuring a
GRETunnel
2. Configure routing profiles
to tunnel traffic through
GRE.
(ap)(config)# routing-profile
(ap)(routing-profile)# route 0.0.0.0 0.0.0.0 <IP of GRE-endpoint>
See
Configuring
Routing
Profiles
3. Configure Enterprise
DNS. The example in the
next column tunnels all
DNS queries to the
client’s original DNS
server without proxying
on W-IAP.
(ap)(config)# internal-domains
(ap)(domains)# domain-name *
See
Configuring
Enterprise
Domains
4. Configure centralized L2
DHCP profile with VLAN
20.
Centralized L2 DHCP profile VLAN 20
(ap)(config)# ip dhcp l2-dhcp
(ap)(DHCP profile "l2-dhcp")# server-type
Centralized,L2
(ap)(DHCP profile "l2-dhcp")# server-vlan 20
See
Configuring a
Centralized
DHCP Scope
5. Create authentication
servers for user
authentication. The
example in the next
column assumes 802.1x
SSID.
(ap)(config)# wlan auth-server server1
(ap)(Auth Server "server1")# ip 10.2.2.1
(ap)(Auth Server "server1")# port 1812
(ap)(Auth Server "server1")# acctport 1813
(ap)(Auth Server "server1")# key "presharedkey"
(ap)(Auth Server "server1")# exit
(ap)(config)# wlan auth-server server2
(ap)(Auth Server "server1")# ip 10.2.2.2
(ap)(Auth Server "server1")# port 1812
(ap)(Auth Server "server1")# acctport 1813
(ap)(Auth Server "server1")# key "presharedkey"
See
Configuring an
External Server
for
Authentication
6. Configure wired and
wireless SSIDs using the
authentication servers
Configure wired ports to operate in centralized L2 mode and
associate VLAN 20 to the wired port profile.
(ap)(config) # wired-port-profile wired-port
See
Configuring a
Wired Profile
Table 75:
W-IAP Configuration for Scenario
Dell Networking W-Series Instant 6.4.0.2-4.1 | User Guide IAP-VPN Deployment Scenarios | 370
Page view 369

Comments to this Manuals

No comments