I skipped over the ESXi part and the initial configuration, but envision you are configuring a router with two physical ports, the VLANs have hardly any meaning, it is more a conduit to have WAN interface and a LAN interface, I did not use these VLANs outside of the controller. Can you post a screenshot of your setup script?
VLAN 500 is the WAN network, I set up a Firewall Zone that allowed this VLAN to communicate with the internet, on my Firewall I used VLAN 31, again keep in mind that VLAN 500 is only significant to the controller, you are free of course to use VLAN 500 as well but it is not required.
VLAN 1500 is the LAN network, this network I allowed to communicate with the LAN networks.
Original Message:
Sent: May 31, 2025 05:01 AM
From: wlaarhov
Subject: Tutorial and observations of deploying a Virtual Gateway (VPNC) on ESXi
Hello Martijn,
Thank you so much for sharing the initial tutorial, it provided already a lot of insights. I am trying to setup a VPNC and have a MicroBranch AP connect to it over Internet.
But i am trying to get my head around your setup and what VLAN has what function. (as I keep breaking things)
And the first and most basic thing probably is: How and via what VLAN/port does system-ip 192.168.190.199 get out?
I am guessing VLAN 500 (connected to 0/0/0) is going through your ISP modem where Port 4500 is port-forwarded inbound. And also that this VLAN500 is used to communicate with Aruba Central?
The Thing I run into constantly trying to replicate this setup for my lab is:
- I break the connection to Aruba Central, so the VPNC becomes isolated (and with that breaks the config)
- I break the ability for name resolution (although ALL DNS servers I provide can be pinged from CLI)
- But I guess for name-resolution the system-IP is used as "source address".
Apparently the System-IP cannot be on one of the other sub-nets (Either LAN or WAN).
Any hint would be greatly appreciated.
Thanks,
Wim,
Original Message:
Sent: Apr 23, 2024 10:06 AM
From: Martijn van Overbeek
Subject: Tutorial and observations of deploying a Virtual Gateway (VPNC) on ESXi
I thought I would share this information to help fellow Airheads. I had spent many hours trying to set up a Aruba Virtual Gateway as VPNC to function as a comparable alternative to a hardware based Gateway. I observed that the documentation as well as videos that are out there to set up a Hardware gateway will not help you with your virtual gateway. It was Zach Weenig who pointed me in the right direction in this post: Virtual Gateway Not working | SD-WAN (arubanetworks.com)
Before I will show you how I was able to successfully configure the Virtual Gateway, some observations:
- Do not attempt to set up a Virtual gateway without 'kickstarting' it through the basic guided setup.
- Do not expect the WAN tab in "Manage" to populate, there is no WAN interface on a Virtual Gateway.
- Do not create a gateway IP pool to assign your System IPs, it will not work, just assign IP addresses manually.
- Do not change interface settings in Advanced mode (you will receive warnings that you should not change interfaces on Virtual Gateways, so I guess it messes things up).
- Do not attempt to deploy the Virtual gateway in Advanced Guided Setup (you will receive errors).
- Not sure is this was a fluke, but I was unable to configure OSPF in basic mode, however if you switch to advanced mode, you can configure it.
- I was unsuccessful in using ArubaOS_VGW_10.5.1.0_89166, this device would not register in Aruba Central, I used ArubaOS_VGW_10.4.1.1_89267 for this instruction.
- Do not click the "Next" button too quickly, you will receive "internal server errors"
- Have patience, at times it took my 6 hours for the Virtual Gateway's initial sync with the group configuration, once synchronized it works fine and is responsive.
Steps:
Prerequisites:
- Assuming a decent understanding of ESXi
- Follow these steps to install the Virtual Gateway on your ESXi host, this will provide the guidelines on the resources required. Pay special attention to the steps to generate the user data in Aruba Central, this will create your licensed Virtual Gateway:
- Make sure your gateway has internet connectivity and either has a public IP address or you forward port 4500, 500 is not needed
Warning:
Following this manual: Deploying VPNC | Validated Solution Guide (arubanetworks.com), did not result in a working Virtual Gateway, my suggestion is to use the procedure below 😊
Step 1: Create a new VPNC AOS 10 group for VPNCs and Gateways
Go to: Global > Groups click the "+" sign in the upper right corner.
Give your group a name and click "add"
Step 2: Move Virtual Gateway to this group
I did not find this still in the manuals but doing it will help you set up the Virtual Gateway as frictionless as possible.
Go to Global > and click on the "Gear" icon of Groups
Now move your new Virtual Gateway to the newly created and UNCONFIGURED group
If the device says Basic Mode in the upper right corner this means you are actually in Advanced Mode. Change it to Basic Mode by clicking on it, and then press the Guided Setup again.
Step 10 (group level): Assign the VLANs to the appropriate ports
Create VLAN information, I used Access Ports and chose locally significant VLANs. Enabling LLDP is your choice, I did not interfere with the deployment.
------------------------------
Martijn van Overbeek
Architect, Netcraftsmen a BlueAlly Company
------------------------------