Users Guide

Table Of Contents
Dell Networking W-Series ArubaOS 6.5.x | User Guide Instant AP VPN Support | 1033
Chapter 40
Instant AP VPN Support
ArubaOS is the companion controller release for the Dell Instant release. This release provides an ability to
terminate VPN and GRE tunnels from Instant AP (IAP) and provide corporate connectivity to the branch IAP
network. For more details, see the Dell Networking W-Series Instant User Guide .
VPN features are ideal for:
l enterprises with many branches that do not have a dedicated VPN connection to the Head Quarter.
l branch offices that require multiple APs.
l individuals working from home, connecting to the VPN.
This new architecture and form factor seamlessly adds the survivability feature of Instant APs with the VPN
connectivity of RAPs providing corporate connectivity to branches.
This section includes the following topics:
l Overview on page 1033
l VPN Configuration on page 1037
l Viewing Branch Status on page 1038
Overview
This section provides a brief summary of the new features included in ArubaOS to support VPN termination
from IAP.
Improved DHCP Pool Management
IAP allows you to configure the DHCP address assignment for the branches connected to the corporate
network through VPN. In distributed DHCP mode, ArubaOS 6.3 allows designated blocks of IP addresses for
static IP users by excluding them from the DHCP scope. In addition, it allows creation of scope of any required
size, thereby enabling more efficient utilization of IP address across branches. For detailed information on
Distributed DHCP for IAP-VPN, see Dell Networking W-Series Instant User Guide.
Termination of Instant AP VPN Tunnels
You can configure IAPs to terminate VPN tunnels on controllers. When configured, the IAP cluster creates a
tunnel from the Virtual Controller (VC) to aDell controller. However, the controller only acts as a VPN end-point
and does not configure the IAP. For more information on how to create a VPN tunnel from a VC to aDell
controller, see Dell Networking W-Series Instant User Guide.
Termination of IAP GRE Tunnels
IAPs have the ability to terminate GRE tunnels on controllers. The IAP cluster creates a tunnel from the VC to
the controller in your corporate office. The controller only acts as a GRE end-point and does not configure the
IAP. For more information on how to create a GRE tunnel from VC to the controller, see the Dell Networking W-
Series Instant Guide.
L2/L3 Network Mode Support
The IAP functioning as a VC enables different DHCP pools (various deployment models) in addition to
allocating IP subnets to each branch.