Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

VIA/VPN

This thread has been viewed 6 times
  • 1.  VIA/VPN

    Posted Jun 06, 2016 11:36 AM

    Hi all,

     

    A customer is looking to have users create VPN tunnels on their laptops and then terminate the tunnels on a VPN concentrator on another site, which is not an Aruba device.  Am I right in saying in this case they do not require the VIA/VPN licence for the controller?

     

    As I understand it the VIA/VPN licence is only needed if the controller is terminating the tunnel, is that right?

     

    Thanks,

    Jamie.



  • 2.  RE: VIA/VPN

    EMPLOYEE
    Posted Jun 06, 2016 11:38 AM
    VIA is a feature license for Aruba controllers. If you're not using VIA, you don't need the license. 


  • 3.  RE: VIA/VPN

    Posted Jun 06, 2016 11:56 AM

    Thanks for the reply Tim, so when you say "if you are not using VIA" - I assume you mean if you are not terminating the VPN tunnel on the controller you are not using VIA?  Sorry if this seems obvious, but I am new to Aruba.

     

    Thanks,

    Jamie.



  • 4.  RE: VIA/VPN

    EMPLOYEE
    Posted Jun 06, 2016 12:00 PM
    VIA is a VPN service for clients and requires a license to enable it on the controller. 

    Basic site to site VPNs can be built on the controller without this license. 

    The only time you need PEFV is if you want to use the VIA client on your end user devices or if you want to customize the VPN tunnel firewall policy for site to site. 

    If your clients are terminating to a 3rd party VPN concentrator, this is just standard user traffic traversing the controller. Nothing is needed on the Aruba side. 


  • 5.  RE: VIA/VPN

    Posted Jun 07, 2016 10:16 AM

    Thanks again Tim.  1 last question on this, even though they are terminating the VPN overseas, if they want to apply PEF rules to the controller (i.e. limit to TCP wireless traffic locally and then VPN overseas) would they then require the VPN licence?  Or would they just require LIC-PEF?

     

    Thanks,

    Jamie.



  • 6.  RE: VIA/VPN

    EMPLOYEE
    Posted Jun 07, 2016 10:18 AM
    If you want to use the stateful firewall, you will need LIC-PEF x number of
    APs.