We have several branch locations where we have been running S1500 MAS switches with "Distributed L3 DHCP Scopes", where the branch switch creates a tunnel back to an on-campus controller, and wired clients are handed out an internal IP with DHCP. This is described on page 395 of the ArubaOS 7.4.x User Guide for MAS switches, and it has worked really well for us for small branch deployments.
The config on the S1500 looked like this:
#
crypto aruba-vpn
interface vlan 1
peer-ip [controller.ip.address]
#
ip-profile
route 172.16.0.0 255.240.0.0 ipsec "aruba-vpn" 0
#
ip dhcp aruba-vpn-pool "my-aruba-vpn-pool"
domain-name "mydomain.edu"
lease 1 0 0 0
dns-server 192.168.10.21
dns-server 192.168.10.22
server-type "Distributed,L3"
ip-range 172.31.254.1 172.31.255.255
client-count 50
reserve last 7
#
interface vlan "3"
aruba-vpn-pool-profile "my-aruba-vpn-pool"
#
interface-profile switching-profile "3"
access-vlan 3
native-vlan 3
#
interface gigabitethernet "0/0/0"
switching-profile "3"
#
Looking to eventually replace these older switches, I am trying to get the same or similar functionality from a 3810M switch running 16.05.0007 firmware. I do not see what I am looking for in the documentation. There is a command "aruba-vpn type..." but this looks like it's more for management of the switch, not for routing of clients.
Can anyone tell me if the "new" Aruba switches support "Distributed DHCP Scopes" or something similar?