Requirement:
An existing VGW VPNC may have to be decommissioned and replaced with a new VPNC for various reasons.
The requirement is to restore the same config from old VPNC to the new VPNC.
When the new VPNC is moved to the same group in Central as the old VPNC, it can get all the config done at the group level.
However, the "Device-level" config present in the old VPNC will not be copied to the new VPNC unless the changes are manually done in the new VPNC at the device-level.
Solution:
- Device-level changes (local-overrides) need to be copied from the old VPNC and pushed to the new VPNC through API after making make necessary changes.
- Change the DC Preference for the BGW Groups and point to the new VPNC so that it can form IPsec tunnel to the new VPNC.
Configuration:
Step 1:
- Retrieve the "Device-level" (local-override) config for the old VGW VPNC.
- Navigate to "Device-level" of the old VPNC -> Config -> Config Audit -> Local Overrides -> Manage local overrides -> View config Difference.
- Copy all the local overrides to a text file.
Step 2:
Step 3:
- Remove the vgw_est_srv config from the config.
- The new VGW will have its own vgw_est_srv profile which is unique to each device.
- Hence remove the vgw_est_srv profile config from the local-override config of the old VPNC as this profile need not be pushed to the new VPNC.
- Remove the below config completely from the text file from Step-1.
-
est profile vgw_est_srv
password d81aa10f53836201e57af68c31c01c9088c834d2c260a37966aabe50f7be3f068720a4e9db16a56ea175ba389145f3b77895a0495b3969a5
username VG22102xxxxx,02:1A:1E:xx:xx:xx,MC-VA,VGW
Step 4:
- Deploy the new instance of VGW (VPNC) in Aruba Central.
Note:
- If there is additional license available, proceed with this step.
- If there is no additional license available, delete the old VGW deployment so that license will be available to accommodate the new VPNC.
Step 5:
- Push the config in the text file to the new VPNC using API.
Step 6:
- Ensure that the new VPNC has the connectivity to reach Central.
Step 7:
- Navigate to the Branch group(s) -> VPN -> SDWAN Overlay and change the DC Preference.
- Remove the old VPNC from DC preference and point the new VPNC.
Verification
Navigate to "Device-level" of the new VPNC -> Config -> Config Audit -> Local Overrides -> Manage local overrides -> View config Difference.
Check and confirm if the new device has all the local-overrides which were pushed through API.