AP-VPN Deployment Scenarios
35.2 Scenario 2 - IPsec: Single Datacenter with Multiple controllers for Redundancy
SCALANCE W1750D UI
Configuration Manual, 02/2018, C79000-G8976-C451-02
535
35.2
Scenario 2 - IPsec: Single Datacenter with Multiple controllers for
Redundancy
This scenario includes the following configuration elements:
●
A VRRP instance between the master/standby-master pair, which is configured as the
primary VPN IP address.
●
Tunneling of all traffic to datacenter.
●
Exception route to bypass tunneling of RADIUS and AirWave traffic, which are locally
reachable in the branch and the Internet, respectively.
●
All client DNS queries are tunneled to the controller.
●
Distributed, L3 and Centralized, L2 mode DHCP on all branches. L3 is used by the
employee network and L2 is used by the guest network with captive portal.
●
Wired and wireless users in L2 and L3 modes.
●
Access rules defined for wired and wireless networks.