Controllerless Networks

Reply
og
Occasional Contributor I
Posts: 9
Registered: ‎05-20-2010

Instant with IPSEC Tunnel to Controller

Hi there,

I would like to use IAPs for a customer with many branches. I plan to use a small controller at the central site as VPN concentrator for the IAPs for central outbreak guest access.

To choose the right controller I need to know if  every IAP in an IAP group opens his own IPSEC Tunnel or is only the master opening one per IAP grp.

Which license is needed on the central controller that is only doing vpn termination. In my opinion just one PEFNG should be enough to enable VPN.

 

regards

Oliver

 

 

Moderator
Posts: 681
Registered: ‎04-16-2009

Re: Instant with IPSEC Tunnel to Controller

The VC of an IAP group will create a single IPSec tunnel to the controller.

 

With AOS 6.2 running on the controller there are no licenses specifically needed.  The VPN concentrator function is part of the Base OS.  There was a bug, however, in the 6.1 Technology Release, and PEFV was a workaround.

Occasional Contributor II
Posts: 13
Registered: ‎07-31-2013

Re: Instant with IPSEC Tunnel to Controller

Is it only possible to set-up an IPSec tunnel to an Aruba controller from IAP or is it possible to any IPSec capable node?

MVP
Posts: 4,307
Registered: ‎07-20-2011

Re: Instant with IPSEC Tunnel to Controller


Yes to both questions

Here you go :
http://www.arubanetworks.com/techdocs/InstantMobile/Advanced/Content/Instant%20User%20Guide%20-%20volumes/VPN_Configuration.htm
Thank you

Victor Fabian
Lead Mobility Engineer @ Integration Partners
AMFX | ACMX | ACDX | ACCX | CWAP | CWDP | CWNA
Occasional Contributor II
Posts: 13
Registered: ‎07-31-2013

Re: Instant with IPSEC Tunnel to Controller

I have tried to create an IPSEC tunnel to a firewall, but without success. I can not set any pre-shared keys and I do not understand how to use and load certificates in order to create IPSEC tunnels to a FW.

 

The manual does not show any details unfortunately.

 

Any suggestions?

 

 

Frequent Contributor I
Posts: 97
Registered: ‎04-13-2009

Re: Instant with IPSEC Tunnel to Controller

It is not true that IAP can create IPSec to the firewall. You can do Instant VPN only between Instant VC and Aruba Controller, however in 6.2.1.0-3.4 there is a support for L2TPv3. 

Regards, 

Marek Krauze, CWNE# 174, ACMX #295, ACDX #356
Something cool, helpful or interesting in my post - click the Kudos Star.
Helped to solve your problem - Click Accept as Solution
Search Airheads
Showing results for 
Search instead for 
Did you mean: