AP-VPN Deployment Scenarios
35.1 Scenario 1 - IPsec: Single Datacenter Deployment with No Redundancy
SCALANCE W1750D UI
532
Configuration Manual, 02/2018, C79000-G8976-C451-02
AP Configuration
The following table provides information on the configuration steps performed through the
CLI with example values. For information on the UI procedures, see the topics referenced in
the
UI Procedure
column.
Table 35- 1 AP Configuration for Scenario 1—IPsec: Single Datacenter Deployment with No Redundancy
Configuration Steps
CLI Commands
UI Procedure
1. Configure the primary host for VPN
with the Public VRRP IP address of
the controller.
(scalance)(config)# vpn primary <public
VRRP IP of controller>
See Configuring an IPsec
Tunnel
2. Configure a routing profile to tunnel
all 10.0.0.0/8 subnet traffic to control-
ler.
(scalance)(config)# routing-profile (scal-
ance)(routing-profile)# route 10.0.0.0
255.0.0.0 <public VRRP IP of controller>
See Configuring Routing
Profiles
3. Configure Enterprise DNS for split
DNS. The example in the next column
uses a specific enterprise domain to
only tunnel all DNS queries matching
that domain to corporate.
(scalance)(config)# internal-domains
(scalance)(domains)# domain-name corpdo-
main.com
See Configuring Enterprise
Domains
4. Configure Centralized, L2 and
Distributed, L3 with
VLAN 20 and VLAN 30, respectively.
Centralized, L2 profile
(scalance)(config)# ip dhcp l2-dhcp
(scalance)(DHCP Profile "l2-dhcp")# server-
type Centralized,L2
(scalance)(DHCP Profile "l2-dhcp")# server-vlan 20
Distributed, L3 profile
(scalance)(config)# ip dhcp l3-dhcp
(scalance)(DHCP Profile "l3-dhcp")# server-
type Distributed,L3
(scalance)(DHCP Profile "l3-dhcp")# server-
vlan 30
(scalance)(DHCP Profile "l3-dhcp")# ip-
range
10.30.0.0 10.30.255.255
(scalance)(DHCP Profile "l3-dhcp")# dns-
server
10.1.1.50,10.1.1.30
(scalance)(DHCP Profile "l3-dhcp")# domain-
name
corpdomain.com
(scalance)(DHCP Profile "l3-dhcp")# client-
count
200
NOTE: The IP range configuration on each branch
will be the same. Each AP will derive a smaller sub-
net based on the client count scope using the
Branch ID (BID) allocated by controller.
See Configuring Central-
ized DHCP Scopes
and Configuring Distributed
DHCP Scopes
Содержание SCALANCE W1750D UI
Страница 18: ...About this guide SCALANCE W1750D UI 18 Configuration Manual 02 2018 C79000 G8976 C451 02 ...
Страница 28: ...About SCALANCE W 3 3 SCALANCE W CLI SCALANCE W1750D UI 28 Configuration Manual 02 2018 C79000 G8976 C451 02 ...
Страница 108: ...IPv6 Support 10 4 Debugging Commands SCALANCE W1750D UI 108 Configuration Manual 02 2018 C79000 G8976 C451 02 ...
Страница 326: ......
Страница 356: ......
Страница 374: ......
Страница 416: ......
Страница 440: ......
Страница 450: ...Intrusion Detection 27 4 Configuring IDS SCALANCE W1750D UI 450 Configuration Manual 02 2018 C79000 G8976 C451 02 ...
Страница 470: ......
Страница 480: ......
Страница 496: ......
Страница 518: ...Hotspot Profiles 33 3 Sample Configuration SCALANCE W1750D UI 518 Configuration Manual 02 2018 C79000 G8976 C451 02 ...
Страница 528: ......
Страница 552: ......
Страница 570: ...Appendix B 3 Glossary SCALANCE W1750D UI 570 Configuration Manual 02 2018 C79000 G8976 C451 02 ...