Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Single IP subnet for clients of L2 cluster with NAT

This thread has been viewed 0 times
  • 1.  Single IP subnet for clients of L2 cluster with NAT

    Posted Apr 12, 2018 09:31 AM

    Could someone, please, clarify me two questions regarding cluster of controllers running AOS8.

     

    Cluster of 2 controller, L2 connected. Both controllers perfom a NAT/PAT function.
    1. Can a clients be in the same IP subnet on both controllers or is it neccessary to divide it in two?
    2. Is there a way to move failed controller's external IP to remaining controller or to share one external IP address on both controllers?

     

    If there is a design guide that explain this in examples, please point it to me, because I haven't find any.



  • 2.  RE: Single IP subnet for clients of L2 cluster with NAT

    Posted Apr 12, 2018 10:03 AM
    - You shouldn’t have the clients subnet be on the same subnet as the controller to avoid issues from security and performance perspective .

    - NAT is not supported for clustered controller in AOS 8


    Pardon typos sent from Mobile


  • 3.  RE: Single IP subnet for clients of L2 cluster with NAT

    Posted Apr 16, 2018 09:48 AM
      |   view attached

    Thank you, Victor.

    Probably I had to put a diagram to make myself clearer. It's better later than never. Diagram is in the attachment. Client's addresses are in different subnets.

    If I'm going to use NAT function on a controllers I'll just use them without forming a cluster? Or is it not recommended?


    Thank you in advance!

     

    Alexander Suntsev.

     



  • 4.  RE: Single IP subnet for clients of L2 cluster with NAT

    Posted Apr 16, 2018 09:56 AM
    If I'm going to use NAT function on a controllers I'll just use them without forming a cluster? Or is it not recommended?
    NAT won’t work just because of how clustering behaves

    If you really need the clustering feature then I suggest you have a separate controller or pair of controllers (not part of the cluster) handle your vpn connections



    Pardon typos sent from Mobile