
(Instant Access Point)(config)# vpn reconnect-user-on-failover
(Instant Access Point)(config)# vpn reconnect-time-on-failover <down_time>
(Instant Access Point)(config)# end
(Instant Access Point)# commit apply
Example
(Instant Access Point)(config)# vpn primary 192.0.2.18
(Instant Access Point)(config)# vpn backup 192.0.2.18
(Instant Access Point)(config)# vpn fast-failover
(Instant Access Point)(config)# vpn preemption
(Instant Access Point)(config)# ip dhcp distl2
(Instant Access Point)(DHCP Profile "distL2")# server-type Distributed,L2
(Instant Access Point)(DHCP Profile "distL2")# server-vlan 2
(Instant Access Point)(DHCP Profile "distL2")# ip-range 10.15.205.0 10.15.205.255
(Instant Access Point)(DHCP Profile "distL2")# subnet-mask 255.255.255.0
(Instant Access Point)(DHCP Profile "distL2")# lease-time 86400
(Instant Access Point)(DHCP Profile "distL2")# default-router 10.15.205.254
(Instant Access Point)(DHCP Profile "distL2")# dns-server 10.13.6.110,10.1.1.50
(Instant Access Point)(DHCP Profile "distL2")# domain-name alcatel-lucent.com
(Instant Access Point)(DHCP Profile "distL2")# client-count 5
(Instant Access Point)(config)# ip dhcp local
(Instant Access Point)(DHCP Profile "local")# server-type Local
(Instant Access Point)(DHCP Profile "local")# server-vlan 200
(Instant Access Point)(DHCP Profile "local")# subnet 172.16.200.1
(Instant Access Point)(DHCP Profile "local")# subnet-mask 255.255.255.0
(Instant Access Point)(DHCP Profile "local")# lease-time 86400
(Instant Access Point)(DHCP Profile "local")# dns-server 10.13.6.110,10.1.1.50
(Instant Access Point)(DHCP Profile "local")# domain-name alcatel-lucent.com
To view VPN configuration:
Instant Access Point# show vpn config
Enabling Automatic Configuration of GRETunnel
GRE is an Alcatel-Lucent proprietary tunnel protocol for encapsulating multicast, broadcast, and L2 packets
between the Switch and OAW-IAPs. The automatic GRE feature uses the IPSec connection between OAW-IAP
and switch to send the control information for setting up a GRE tunnel. When automatic GRE configuration is
enabled, a single IPSec tunnel between the OAW-IAP cluster and switch and one or several GRE tunnels are
created based on the Per-AP tunnel configuration on the OAW-IAP. When this feature is enabled on the OAW-IAP,
no manual configuration is required on switch to create the GRE tunnel.
Automatic configuration of GRE tunnel is supported only on Alcatel-Lucent switchs. This feature is not supported
on switches running AOS-W Instant 6.3.x.x or lower versions.
You can configure an OAW-IAP to automatically set up a GRE tunnel from the OAW-IAP to Switch by using AOS-W
Instant UI or CLI.
In the AOS-W Instant UI
1. Click the More>VPN link at the top right corner of the AOS-W Instant UI. The Tunneling window is displayed.
2. Select Aruba GRE from the Protocol drop-down list.
3. Enter the IP address or FQDN for the main VPN/IPSec endpoint in the Primary host field.
4. Enter the IP address or FQDN for the backup VPN/IPSec endpoint in the Backup host field. This entry is
optional. When you enter Primary host IP address, Backup host IP address, other fields are displayed.
5. Specify the following parameters. A sample configuration is shown in Figure 80.
AOS-W Instant 6.3.1.1-4.0 | User Guide VPN Configuration | 241
Komentarze do niniejszej Instrukcji