Dell W-Series 334 Instant 6.5.1.0-4.3.1.0 User Guide - Page 396

Configuration Steps, CLI Commands, UI Procedure

Page 396 highlights

Table 84: W-IAP Configuration for Scenario 1-IPsec: Single Datacenter Deployment with No Redundancy Configuration Steps CLI Commands UI Procedure 1. Configure the primary host for VPN with the Public VRRP IP address of the controller. (Instant AP)(config)# vpn primary See Configuring an IPsec Tunnel 2. Configure a routing profile to tunnel all 10.0.0.0/8 subnet traffic to controller. (Instant AP)(config)# routing-profile (Instant AP)(routing-profile)# route 10.0.0.0 255.0.0.0 See Configuring Routing Profiles 3. Configure Enterprise DNS for split DNS. The example in the next column uses a specific enterprise domain to only tunnel all DNS queries matching that domain to corporate. (Instant AP)(config)# internal-domains (Instant AP)(domains)# domain-name corpdomain.com See Configuring Enterprise Domains 4. Configure Centralized, L2 and Distributed, L3 with VLAN 20 and VLAN 30, respectively. Centralized, L2 profile (Instant AP)(config)# ip dhcp l2-dhcp (Instant AP)(DHCP Profile "l2-dhcp")# server-type Centralized,L2 (Instant AP)(DHCP Profile "l2-dhcp")# server-vlan 20 Distributed, L3 profile (Instant AP)(config)# ip dhcp l3-dhcp (Instant AP)(DHCP Profile "l3-dhcp")# server-type Distributed,L3 (Instant AP)(DHCP Profile "l3-dhcp")# server-vlan 30 (Instant AP)(DHCP Profile "l3-dhcp")# ip-range 10.30.0.0 10.30.255.255 (Instant AP)(DHCP Profile "l3-dhcp")# dns-server 10.1.1.50,10.1.1.30 (Instant AP)(DHCP Profile "l3-dhcp")# domain-name corpdomain.com (Instant AP)(DHCP Profile "l3-dhcp")# client-count 200 See Configuring Centralized DHCP Scopes and Configuring Distributed DHCP Scopes NOTE: The IP range configuration on each branch will be the same. Each W-IAP will derive a smaller subnet based on the client count scope using the Branch ID (BID) allocated by controller. 5. Create authentication servers for user authentication. The example in the next column assumes 802.1X SSID. (Instant AP)(config)# wlan auth-server server1 (Instant AP)(Auth Server "server1")# ip 10.2.2.1 (Instant AP)(Auth Server "server1")# port 1812 (Instant AP)(Auth Server "server1")# acctport 1813 (Instant AP)(Auth Server "server1")# key "presharedkey" (Instant AP)(Auth Server "server1")# exit See Configuring an External Server for Authentication (Instant AP)(config)# wlan auth-server server2 (Instant AP)(Auth Server "server2")# ip 10.2.2.2 (Instant AP)(Auth Server "server2")# port 1812 Dell Networking W-Series Instant 6.5.1.0-4.3.1.0 | User Guide IAP-VPN Deployment Scenarios | 396

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435

Configuration Steps
CLI Commands
UI Procedure
1.
Configure the primary
host for VPN with the
Public VRRP IP address of
the controller.
(Instant AP)(config)# vpn primary <public VRRP IP of
controller>
See
Configuring an
IPsec Tunnel
2.
Configure a routing
profile to tunnel all
10.0.0.0/8 subnet traffic
to controller.
(Instant AP)(config)# routing-profile
(Instant AP)(routing-profile)# route 10.0.0.0
255.0.0.0 <public VRRP IP of controller>
See
Configuring
Routing
Profiles
3.
Configure Enterprise
DNS for split DNS. The
example in the next
column uses a specific
enterprise domain to
only tunnel all DNS
queries matching that
domain to corporate.
(Instant AP)(config)# internal-domains
(Instant AP)(domains)# domain-name corpdomain.com
See
Configuring
Enterprise
Domains
4.
Configure Centralized, L2
and Distributed, L3 with
VLAN 20 and VLAN 30,
respectively.
Centralized, L2 profile
(Instant AP)(config)# ip dhcp l2-dhcp
(Instant AP)(DHCP Profile "l2-dhcp")# server-type
Centralized,L2
(Instant AP)(DHCP Profile "l2-dhcp")# server-vlan 20
Distributed, L3 profile
(Instant AP)(config)# ip dhcp l3-dhcp
(Instant AP)(DHCP Profile "l3-dhcp")# server-type
Distributed,L3
(Instant AP)(DHCP Profile "l3-dhcp")# server-vlan 30
(Instant AP)(DHCP Profile "l3-dhcp")# ip-range
10.30.0.0 10.30.255.255
(Instant AP)(DHCP Profile "l3-dhcp")# dns-server
10.1.1.50,10.1.1.30
(Instant AP)(DHCP Profile "l3-dhcp")# domain-name
corpdomain.com
(Instant AP)(DHCP Profile "l3-dhcp")# client-count
200
NOTE:
The IP range configuration on each branch will be the
same. Each W-IAP will derive a smaller subnet based on the client
count scope using the Branch ID (BID) allocated by controller.
See
Configuring
Centralized
DHCP Scopes
and
Configuring
Distributed
DHCP Scopes
5.
Create authentication
servers for user
authentication. The
example in the next
column assumes 802.1X
SSID.
(Instant AP)(config)# wlan auth-server server1
(Instant AP)(Auth Server "server1")# ip 10.2.2.1
(Instant AP)(Auth Server "server1")# port 1812
(Instant AP)(Auth Server "server1")# acctport 1813
(Instant AP)(Auth Server "server1")# key
"presharedkey"
(Instant AP)(Auth Server "server1")# exit
(Instant AP)(config)# wlan auth-server server2
(Instant AP)(Auth Server "server2")# ip 10.2.2.2
(Instant AP)(Auth Server "server2")# port 1812
See
Configuring an
External Server
for
Authentication
Table 84:
W-IAP Configuration for Scenario 1—IPsec: Single Datacenter Deployment with No Redundancy
Dell Networking W-Series Instant 6.5.1.0-4.3.1.0 | User Guide
IAP-VPN Deployment Scenarios |
396