Dell PowerConnect W-IAP92 Dell Instant 6.2.0.0-3.2.0.0 User Guide - Page 262

Fast Failover, Routing Profile Configuration, Primary host

Page 262 highlights

1. Navigate to the VPN link at the top right corner of the Dell W-Series Instant UI. The Tunneling window appears. 2. Select IPSec from the Protocol drop-down list. 3. If you select GRE from the Protocol drop-down list then the packets are sent and received without encryption. a. GRE type - Enter the value for GRE type parameter. b. Per-AP tunnel - Select Enabled or Disabled from the Per-AP tunnel drop-down list. The user can create GRE tunnels from all of the APs instead of creating tunnels only from the AP that is acting as the Virtual Controller. The traffic going to the corporate is sent via L2 GRE tunnel from the AP itself and does not have to be forwarded through the Virtual Controller. NOTE: By default, the Per-AP tunnel option is disabled. 4. Enter the IP address or fully qualified domain name for the main VPN/GRE endpoint in the Primary host field. 5. Enter the IP address or fully qualified domain name for the backup VPN endpoint in the Backup host field. This entry is optional. 6. Select Enabled from the Preemption drop-down list to switch back to the primary host when and if it becomes available again. This step is optional. 7. Select Enabled or Disabled from the Fast failover drop-down list. 8. Enter Connection test frequency at which packets are sent to the controller. The unit is seconds per packet and the default value is 10 seconds which means that every 10 seconds the W-IAP will send one packet to the controller. NOTE: This value should be less than L3 user time out value in the Dell Controller. For example, if L3 user timeout in the Dell Controller is 5 minutes, the Connection test frequency should be less than 300 seconds. 9. Enter Test packet count which is the number of lost packets and after which the W-IAP will make the tunnel down. The default value is 2. 10. Click Next to continue. Fast Failover Enabling the fast failover feature allows the W-IAP to create a backup VPN tunnel to the controller along with the primary tunnel, and maintain both the primary and backup tunnel separately. If the primary tunnel fails, the W-IAP can switch the data stream to the backup tunnel. This reduces the total failover time to less than one minute. Routing Profile Configuration W-Instant can terminate a single VPN connection on an Dell PowerConnect W-Series Mobility Controller. The Routing profile defines the corporate subnets which need to be tunneled through the IPSec tunnel. 262 | VPN Configuration Dell PowerConnect W-Series Instant Access Point 6.2.0.0-3.2.0.0 | User Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296

262
|
VPN Configuration
Dell PowerConnect W-Series Instant Access Point
6.2.0.0-3.2.0.0
|
User Guide
1.
Navigate to the
VPN
link at the top right corner of the Dell W-Series Instant UI. The
Tunneling
window appears.
2.
Select
IPSec
from the
Protocol
drop-down list.
3.
If you select
GRE
from the
Protocol
drop-down list then the packets are sent and received
without encryption.
a.
GRE type
— Enter the value for GRE type parameter.
b.
Per-AP tunnel
— Select
Enabled
or
Disabled
from the
Per-AP tunnel
drop-down list.
The user can create GRE tunnels from all of the APs instead of creating tunnels only from
the AP that is acting as the Virtual Controller. The traffic going to the corporate is sent via
L2 GRE tunnel from the AP itself and does not have to be forwarded through the Virtual
Controller.
NOTE: By default, the
Per-AP tunnel
option is disabled.
4.
Enter the IP address or fully qualified domain name for the main VPN/GRE endpoint in the
Primary host
field.
5.
Enter the IP address or fully qualified domain name for the backup VPN endpoint in the
Backup host
field. This entry is optional.
6.
Select
Enabled
from the
Preemption
drop-down list to switch back to the primary host when
and if it becomes available again. This step is optional.
7.
Select
Enabled
or
Disabled
from the
Fast failover
drop-down list.
8.
Enter
Connection test frequency
at which packets are sent to the controller. The unit is
seconds per packet and the default value is 10 seconds which means that every 10 seconds the
W-IAP will send one packet to the controller.
NOTE: This value should be less than L3 user time out value in the Dell Controller. For
example, if L3 user timeout in the Dell Controller is 5 minutes, the Connection test frequency
should be less than 300 seconds.
9.
Enter
Test packet count
which is the number of lost packets and after which the W-IAP will
make the tunnel down. The default value is 2.
10. Click
Next
to continue.
Fast Failover
Enabling the fast failover feature allows the W-IAP to create a backup VPN tunnel to the
controller along with the primary tunnel, and maintain both the primary and backup tunnel
separately. If the primary tunnel fails, the W-IAP can switch the data stream to the backup
tunnel. This reduces the total failover time to less than one minute.
Routing Profile Configuration
W-Instant can terminate a single VPN connection on an Dell PowerConnect W-Series Mobility
Controller. The Routing profile defines the corporate subnets which need to be tunneled through
the IPSec tunnel.