397
| IAP-VPN Deployment Scenarios
Aruba Instant 6.5.0.0-4.3.0.0 | User Guide
Scenario 1—IPsec: Single Datacenter Deployment with No
Redundancy
This scenario includes the following configuration elements:
1. Single VPN primary configuration using IPsec.
2. Split-tunneling of client traffic.
3. Split-tunneling of DNS traffic from clients.
4. Distributed, L3 and Centralized, L2 mode DHCP.
5. RADIUS server within corporate network and authentication survivability for branch survivability.
6. Wired and wireless users in L2 and L3 modes, respectively.
7. Access rules defined for wired and wireless networks to permit all traffic.
Topology
shows the topology and the IP addressing scheme used in this scenario.
Figure 123
Scenario 1—IPsec: Single datacenter Deployment with No Redundancy
The following IP addresses are used in the examples for this scenario:
l
10.0.0.0/8 is the corporate network
l
10.20.0.0/16 subnet is reserved for L2 mode
l
10.30.0.0/16 subnet is reserved for L3 mode
l
Client count in each branch is 200
IAP Configuration
The following table provides information on the configuration steps performed through the CLI with example
values. For information on the UI procedures, see the topics referenced in the
UI Procedure
column.