Wired Intelligent Edge

last person joined: 20 hours ago 

Bring performance and reliability to your network with the HPE Aruba Networking Core, Aggregation, and Access layer switches. Discuss the latest features and functionality of your switching devices, and find ways to improve security across your network to bring together a mobile-first solution
Expand all | Collapse all

MAS: Tunneled node or L2 GRE

This thread has been viewed 0 times
  • 1.  MAS: Tunneled node or L2 GRE

    Posted Oct 07, 2015 02:31 PM

    Scenario:

    Contractors/Guests are connecting to several layer3 MAS across a campus.  Their traffic needs to physically flow from the MAS to the data center controllers and out an unrouted VLAN with an ISP connection dedicated to guests.  Since the guests are sharing the same infrastructure as the company, logical separation of traffic is necessary.  To accomplish this, encapsulation will be used.  Which is appropriate in this case?  Tunneled node or L2 GRE to controller?

     

    I've setup L2 GRE tunnels between controllers before to span a wireless network, but haven't tried this with a MAS yet.  I assume it would work just the same, but I also know I have tunneled mode available on the MAS.  As far as I can tell, it's very similar since GRE tunnels are used, but there is the benefit of having all of the policy enforcement done in one place - the controller.  That may not even factor in, so then what is the benefit in choose tunneled mode, as opposed to just setting up an L2 GRE?



  • 2.  RE: MAS: Tunneled node or L2 GRE

    EMPLOYEE
    Posted Oct 07, 2015 02:37 PM
    Tunneled node handles authentication at the controller level instead of the switch. 


    Thanks, 
    Tim


  • 3.  RE: MAS: Tunneled node or L2 GRE

    Posted Oct 07, 2015 02:44 PM

    If the devices aren't authenticating, do you see any benefit over one solution?



  • 4.  RE: MAS: Tunneled node or L2 GRE

    Posted Oct 07, 2015 02:48 PM

    For instance, the tunneled node option allows a backup controller to be specified.  L2 GRE doesn't.  Would VRRP between the controllers be the solution?