Concept Guide
242 | IAP-VPN Deployment Dell Networking W-Series Instant 6.4.3.1-4.2.0.0 | User Guide
DHCP Scope and VPN Forwarding Modes Mapping
The following table provides a summary of the DHCP scope and VPN forwarding modes mapping:
Local
Local
L2
Local
L3
Centralized
L2
Centralized
L3
Distributed
L2
Distributed
L3
DHCP
server
Virtual
Controller
Virtual
Controller
Virtual
Controller
DHCP Server in
the Datacenter
DHCP Server in
the Datacenter
and VC acts as
a relay agent
Virtual
Controller
Virtual
Controller
Default
Gateway
for clients
Virtual
Controller
Default
Gateway
in the
local
network
Virtual
Controller
Controller or a
router in the
Datacenter
Virtual
Controller
Controller or a
router in the
Datacenter
Virtual
Controller
Corporate
Traffic
SNAT is
performed
with inner
IP of the
IPSec
tunnel
Not
applicable
SNAT is
performed
with inner
IP of the
IPSec
tunnel
L2 reachable Routed L2 reachable Routed
Internet
Traffic
SNAT is
performed
with local
IP of the
Virtual
Controller
Locally
bridged
Routed SNAT is
performed
with local IP of
the Virtual
Controller
SNAT is
performed
with local IP of
the Virtual
Controller
SNAT is
performed
with local IP of
the Virtual
Controller
SNAT is
performed
with local IP of
the Virtual
Controller
Branch
access
from
datacenter
No No No Yes Yes Yes Yes
Table 46: DHCP Scope and VPN Forwarding Modes Matrix
Configuring W-IAP and Controller for IAP-VPN Operations
This section describes the configuration procedures to perform on the W-IAP and controller for generic use
cases. For information on specific deployment scenarios, see IAP-VPN Deployment Scenarios on page 380.
Configuring a W-IAP network for IAP-VPN operations
This section describes the configuration procedures to perform on the W-IAP for generic use cases. For
information on specific deployment scenarios, see IAP-VPN Deployment Scenarios on page 380.
A W-IAP network requires the following configuration for IAP-VPN operations.
1. Defining the VPN host settings
2. Configuring Routing Profiles
3. Configuring DHCP Profiles
4. Configuring an SSID or Wired Port