Dell W-Series 228 Instant 6.4.3.1-4.2 User Guide - Page 228

In the CLI, Example, Configuring an L2-GRE Tunnel, Configuring Manual GRE Parameters

Page 228 highlights

6. Click Next to create routing profiles. When the IPsec tunnel configuration is completed, the packets that are sent from and received by a W-IAP are encrypted. In the CLI To configure an IPSec VPN tunnel: (Instant AP)(config)# vpn primary (Instant AP)(config)# vpn backup (Instant AP)(config)# vpn fast-failover (Instant AP)(config)# vpn hold-time (Instant AP)(config)# vpn preemption (Instant AP)(config)# vpn monitor-pkt-send-freq (Instant AP)(config)# vpn monitor-pkt-lost-cnt (Instant AP)(config)# vpn reconnect-user-on-failover (Instant AP)(config)# vpn reconnect-time-on-failover (Instant AP)(config)# end (Instant AP)# commit apply Example (Instant AP)(config)# vpn primary 192.0.2.18 (Instant AP)(config)# vpn backup 192.0.2.18 (Instant AP)(config)# vpn fast-failover (Instant AP)(config)# vpn preemption (Instant AP)(config)# ip dhcp distl2 (Instant AP)(DHCP Profile "distL2")# server-type Distributed,L2 (Instant AP)(DHCP Profile "distL2")# server-vlan 2 (Instant AP)(DHCP Profile "distL2")# ip-range 10.15.205.0 10.15.205.255 (Instant AP)(DHCP Profile "distL2")# subnet-mask 255.255.255.0 (Instant AP)(DHCP Profile "distL2")# lease-time 86400 (Instant AP)(DHCP Profile "distL2")# default-router 10.15.205.254 (Instant AP)(DHCP Profile "distL2")# dns-server 10.13.6.110,10.1.1.50 (Instant AP)(DHCP Profile "distL2")# domain-name dell.com (Instant AP)(DHCP Profile "distL2")# client-count 5 (Instant AP)(config)# ip dhcp local (Instant AP)(DHCP Profile "local")# server-type Local (Instant AP)(DHCP Profile "local")# server-vlan 200 (Instant AP)(DHCP Profile "local")# subnet 172.16.200.1 (Instant AP)(DHCP Profile "local")# subnet-mask 255.255.255.0 (Instant AP)(DHCP Profile "local")# lease-time 86400 (Instant AP)(DHCP Profile "local")# dns-server 10.13.6.110,10.1.1.50 (Instant AP)(DHCP Profile "local")# domain-name dell.com To view VPN configuration: Instant Access Point# show vpn config Configuring an L2-GRE Tunnel This section describes the following procedures: l Configuring Manual GRE Parameters l Configuring Dell GRE Parameters Configuring Manual GRE Parameters To configure a GRE tunnel between the W-IAP and controller using either the Virtual Controller IP or the W-IAP IP, based on the following W-IAP settings: l If a Virtual Controller IP is configured and if Per-AP tunnel is disabled, use Virtual Controller IP. l If a Virtual Controller IP is not configured or if Per-AP tunnel is enabled, use the W-IAP IP. 228 | VPN Configuration Dell Networking W-Series Instant 6.4.3.1-4.2.0.0 | User Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403

228
| VPN Configuration
Dell Networking W-Series Instant 6.4.3.1-4.2.0.0 | User Guide
6. Click
Next
to create routing profiles. When the IPsec tunnel configuration is completed, the packets that are
sent from and received by a W-IAP are encrypted.
In the CLI
To configure an IPSec VPN tunnel:
(Instant AP)(config)# vpn primary <name>
(Instant AP)(config)# vpn backup <name>
(Instant AP)(config)# vpn fast-failover
(Instant AP)(config)# vpn hold-time <seconds>
(Instant AP)(config)# vpn preemption
(Instant AP)(config)# vpn monitor-pkt-send-freq <frequency>
(Instant AP)(config)# vpn monitor-pkt-lost-cnt <count>
(Instant AP)(config)# vpn reconnect-user-on-failover
(Instant AP)(config)# vpn reconnect-time-on-failover <down_time>
(Instant AP)(config)# end
(Instant AP)# commit apply
Example
(Instant AP)(config)# vpn primary 192.0.2.18
(Instant AP)(config)# vpn backup 192.0.2.18
(Instant AP)(config)# vpn fast-failover
(Instant AP)(config)# vpn preemption
(Instant AP)(config)# ip dhcp distl2
(Instant AP)(DHCP Profile "distL2")# server-type Distributed,L2
(Instant AP)(DHCP Profile "distL2")# server-vlan 2
(Instant AP)(DHCP Profile "distL2")# ip-range 10.15.205.0 10.15.205.255
(Instant AP)(DHCP Profile "distL2")# subnet-mask 255.255.255.0
(Instant AP)(DHCP Profile "distL2")# lease-time 86400
(Instant AP)(DHCP Profile "distL2")# default-router 10.15.205.254
(Instant AP)(DHCP Profile "distL2")# dns-server 10.13.6.110,10.1.1.50
(Instant AP)(DHCP Profile "distL2")# domain-name dell.com
(Instant AP)(DHCP Profile "distL2")# client-count 5
(Instant AP)(config)# ip dhcp local
(Instant AP)(DHCP Profile "local")# server-type Local
(Instant AP)(DHCP Profile "local")# server-vlan 200
(Instant AP)(DHCP Profile "local")# subnet 172.16.200.1
(Instant AP)(DHCP Profile "local")# subnet-mask 255.255.255.0
(Instant AP)(DHCP Profile "local")# lease-time 86400
(Instant AP)(DHCP Profile "local")# dns-server 10.13.6.110,10.1.1.50
(Instant AP)(DHCP Profile "local")# domain-name dell.com
To view VPN configuration:
Instant Access Point# show vpn config
Configuring an L2-GRE Tunnel
This section describes the following procedures:
l
Configuring Manual GRE Parameters
l
Configuring Dell GRE Parameters
Configuring Manual GRE Parameters
To configure a GRE tunnel between the W-IAP and controller using either the Virtual Controller IP or the W-IAP
IP, based on the following W-IAP settings:
l
If a Virtual Controller IP is configured and if
Per-AP tunnel
is disabled, use Virtual Controller IP.
l
If a Virtual Controller IP is not configured or if
Per-AP tunnel
is enabled, use the W-IAP IP.