Users Guide

Table Of Contents
1034| Instant AP VPN Support Dell Networking W-Series ArubaOS 6.5.x| User Guide
IAPs support the following DHCP configuration modes:
l L2 Switching Mode: In this mode, IAP supports distributed L2 and centralized L2 switching modes of
connection to the corporate network. When a IAP registers with the controller and has a L2 mode DHCP
pool configured, the controller automatically adds the GRE or VPN tunnel associated to this IAP into the
VLAN multicast table. This allows the clients connecting to this L2 mode VLAN to be part of the same L2
domain on controller.
l L3 Routing Mode: In this mode, IAP supports L3 routing mode of connection to the corporate network. The
VC assigns an IP addresses from the configured subnet and forwards traffic to both corporate and non-
corporate destinations. The IAP handles the routing on the subnet and also adds a route on the controller
after the VPN tunnel is set up during the registration of the subnet. When the IAP registers with a L3 mode
DHCP pool, the controller automatically adds a route to this DHCP subnet enabling routing of traffic from
the corporate network to clients on this VLAN in the branch.
Instant AP VPN Scalability Limits
ArubaOS provides enhancements to the scalability limits for the IAP VPN branches terminating on the
controller. The following table provides the IAP VPN scalability information for various controller platforms:
Platforms Branches Routes L3 Mode Users NATUsers Total L2 Users
W-7210 8000 8000 64000
W-7220 16000 16000 128000
W-7240 32000 32000 128000
Table 245: Instant AP VPN Scalability Limits
l Branches—The number of IAP VPN branches that can be terminated on a given controller platform.
l Routes—The number of L3 routes supported on the controller.
l L3 mode and NAT mode usersThe number of trusted users supported on the controller. There is no
scale impact on the controller. They are limited only by the number of clients supported per Instant AP.
l L2 mode users—The number of L2 mode users are limited to 128000 for W-7220 and W-7240 and 64000
across all other platforms.
Instant AP VPN OSPF Scaling
ArubaOS allows each IAP VPN to define a separate subnet derived from a corporate intranet pool to allow IAP
VPN devices to work independently. For information on sample topology and configuration, see OSPFv2.
To redistribute IAP VPN routes into the OSPF process, use the following command :
(host)(config) # router ospf redistribute rapng-vpn
To verify if the redistribution of the IAP VPN is enabled, use following command:
(host) #show ip ospf redistribute
Redistribute RAPNG
To configure aggregate route for IAP VPN routes, use the following command:
(host) (config) # router ospf aggregate-route rapng-vpn
To view the aggregated routes for IAPVPN routes, use the following command:
(host) #show ip ospf rapng-vpn aggregate-routes
RAPNG VPN aggregate routes
--------------------------
Prefix Mask Contributing routes Cost