394
Figure 151 Network diagram
Table 17 Interface and IP address assignment
Device
Interface IP
address
Device
Interface IP
address
Hub
1
GE2/0/1 1::1/64
Spoke
1 GE2/0/1 1::4/64
Tunnel1
192:168:1::1/64
GE2/0/2
192:168:10::1/64
Tunnel2 192:168::1/64
Tunnel1 192:168:1::3/64
Hub
2
GE2/0/1 1::2/64
Spoke
2 GE2/0/1 1::5/64
Tunnel1
192:168:1::2/64
GE2/0/2
192:168:20::1/64
Tunnel2
192:168::2/64
GE2/0/3
192:168:30::1/64
Hub 3
GE2/0/1
1::3/64
Tunnel1
192:168:1::4/64
Tunnel1 192:168:2::1/64 Spoke
3 GE2/0/1 1::6/64
Tunnel2
192:168::3/64
GE2/0/2
192:168:40::1/64
AAA
server
1::10/64 Tunnel1
192:168:2::2/64
Primary server
GE2/0/1
1::11/64
Spoke
4 GE2/0/1 1::7/64
Secondary server
GE2/0/1
1::12/64 GE2/0/2
192:168:50::1/64
GE2/0/3
192:168:60::1/64
Tunnel1
192:168:2::3/64
Configuring the primary VAM server
1.
Configure IP addresses for the interfaces. (Details not shown.)
2.
Configure AAA:
AAA server
Hub3
Hub1
Group 1
Group 2
Group 0
Spoke1
Spoke4
Hub2
Tunnel 1
Tunnel 1
Tunnel 1
Tunnel 1
Tunnel 1
Tunnel 1
Spoke2
Spoke3
GE2/0/1
GE2/0/2
GE2/0/1
GE2/0/2
GE2/0/3
GE2/0/1
GE2/0/2
GE2/0/3
GE2/0/1
GE2/0/1
GE2/0/1
GE2/0/1
Tunnel 1
GE2/0/2
Tunnel 2
Tunnel 2
Tunnel 2
Site 1
Site 2
Site 3
Site 4
Site 5
Site 6
Primary server
Secondary server
GE2/0/1
GE2/0/1
Spoke-to-Spoke dynamic tunnel
between two groups
Hub-to-Hub static tunnel
Hub-to-Spoke static tunnel
Spoke-to-Spoke dynamic
tunnel in one group