Internet
WAN Router
WAN Router
Switch being
provisioned
Switch being
provisioned
Router/
Firewall
AirWave
Server
Activate
Secure IPSec
tunnel to
AirW
ave
Secure IPSec tunnel
to AirWave
Corporate
HQ
Branch 2
Branch 1
Aruba
Controller
In the preceding illustration, the workflow is as follows:
1.
The switches being provisioned in the branches are booted and connect to the Activate on the cloud.
2.
Based on the administrator’s provisioning (folder, rule), the device is placed in the appropriate folder before
getting redirected to the AirWave server in the Corporate HQ.
3.
The switches connect to the AirWave server, and the server pushes the configuration to the switches based on
the AirWave folder, switch model, and branch location.
4.
Optionally, an IPsec tunnel to the Controller in the HQ can be constructed to secure the management traffic to
AirWave. This configuration can be set as part of the initial configuration push from Activate.
IPsec for AirWave Connectivity
Overview
This feature supports secure communication between the switch and Aruba mobility controller (VPN concentrator)
for AirWave traffic. The switch also provides the necessary support for ZTP by establishing a secure tunnel
between the switch and AirWave, which are provided by a DHCP server or Activate.
IPsec ensures that communication between the switch and AirWave server (management traffic) is protected by
establishing a secure channel between the switches and the Aruba VPN Controller (connected to AirWave
server).
IPsec for Management Traffic
IPsec supports ZTP in deployment scenarios less restrictive than private LANs. ZTP enables switches to be
configured and managed automatically without administrator intervention. In a deployment scenario where a
switch and AirWave are located in different branches connected through an untrusted public network (the
Internet), the communication between the switch and AirWave server can be protected.
NOTE:
• IPsec tunnel is not supported with IPv6.
• IPsec tunnel is not supported through OOBM.
You can configure IPsec tunnel using any of the following methods:
314
Aruba 2930F / 2930M Management and Configuration Guide
for ArubaOS-Switch 16.08