Cloud Managed Networks

 View Only
  • 1.  Mobility Controller Microbranch termination

    Posted Jan 31, 2025 01:13 PM

    I am reading the HPE7-A01 book which states (page 576 of the hardcopy) that you can terminate microbranch APs on a Mobility Controller if you use manual mode. I did not know that and try to put it to the test.

    The high availability option allows you to set the cluster to manual (see below)

    I can slide a bar stating "VPN termination"

    And I can also configure a Public IP address 

    The next step I thought is adding a microbranch to this gateway cluster
    Unfortunately, whatever I try (build a new microbranch group or use an existing group), I cannot add the cluster to the microbranch.
    What am I doing wrong or is the link below still valid and the HPE7-A01 book incorrect?
    https://community.arubanetworks.com/discussion/does-aos10-gateway-mobility-persona-can-terminate-microbranch


    ------------------------------
    Martijn van Overbeek
    Architect, Netcraftsmen a BlueAlly Company
    ------------------------------


  • 2.  RE: Mobility Controller Microbranch termination

    Posted Jan 31, 2025 03:32 PM

    I don't know what that guide is trying to state, but Microbranch requires the VPNC be in a cluster.

    https://arubanetworking.hpe.com/techdocs/central/2.5.8/content/aos10x/cfg/mb-deploy/mb_data_center_vpnc_conf.htm



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 3.  RE: Mobility Controller Microbranch termination

    Posted Jan 31, 2025 03:45 PM

    Thank you Carson, 

    I am citing the Official Certification Guide, it only speaks about the Mobility Persona. Screenshot below. 

    Can you explain the purpose of the VPN termination button in the mobility persona?



    ------------------------------
    Martijn van Overbeek
    Architect, Netcraftsmen a BlueAlly Company
    ------------------------------



  • 4.  RE: Mobility Controller Microbranch termination

    Posted Jan 31, 2025 04:08 PM

    Microbranch termination is only supported against a VPNC, the mobility persona is dedicated to campus connectivity.  I don't know of a reason for enabling VPN termination on a mobility gateway but I suppose there might be some valid workflow that exists.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 5.  RE: Mobility Controller Microbranch termination

    Posted Jan 31, 2025 05:10 PM

    I looked everywhere but was not able to find how this works 

    The audit trail updated the Gateway with the following configuration:

    lc-cluster group-profile auto_group_374
    no auto-cluster-mode
    no controller 20:4c:03:b2:08:82
    controller 20:4c:03:b2:08:82 priority 128 vrrp-ip 0.0.0.0 rap-public-ip 136.47.197.25
    Could it be that they forgot to remove this from the menu? I wonder I should open a TAC case, I looked everywhere but cannot find any documentation what this VPN termination feature can provide.


    ------------------------------
    Martijn van Overbeek
    Architect, Netcraftsmen a BlueAlly Company
    ------------------------------



  • 6.  RE: Mobility Controller Microbranch termination

    Posted Feb 02, 2025 02:41 PM

    Hi,

    The info in the book is wrong, it has been reported. You don´t need to enable VPN termination.
    You create a new group for micro branch (specific group) and under Data center in that group you tell which VPNC the microbranch AP´s should connect to. Central will orchestrate the setup of tunnels automatically.




  • 7.  RE: Mobility Controller Microbranch termination

    Posted Feb 03, 2025 09:48 AM

    Thanks for clarifying that. I am still curious what the purpose is of that VPN  slide bar for the Mobility controller. But I will let it go 😊, more important things to do that fixate on that slidebar.