User's Manual

Dell Networking W-Series ArubaOS 6.4.x| User Guide Instant AP VPN Support | 978
Chapter 40
Instant AP VPN Support
ArubaOS is the companion controller release for the Dell Instant release. This release provides an ability to
terminate VPN and GRE tunnels from Instant AP and provide corporate connectivity to the branch Instant AP
network. For more details, see the Dell Networking W-Series Instant Access Point User Guide .
VPN features are ideal for:
l enterprises with many branches that do not have a dedicated VPN connection to the Head Quarter.
l branch offices that require multiple APs.
l individuals working from home, connecting to the VPN.
This new architecture and form factor seamlessly adds the survivability feature of Instant APs with the VPN
connectivity of RAPs providing corporate connectivity to branches.
This documentation for this feature includes the following topics:
l Overview on page 978
l VPN Configuration on page 982
l Viewing Branch Status on page 983
Overview
This section provides a brief summary of the new features included in ArubaOS to support VPN termination
from Instant AP.
Improved DHCP Pool Management
Instant AP (IAP) allows you to configure the DHCP address assignment for the branches connected to the
corporate network through VPN. In distributed DHCP mode, ArubaOS 6.3 allows designated blocks of IP
addresses for static IP users by excluding them from the DHCP scope. In addition, it allows creation of scope of
any required size, thereby enabling more efficient utilization of IP address across branches. For detailed
information on Distributed DHCP for IAP-VPN, see Dell Networking W-Series Instant Access Point User Guide.
Termination of Instant AP VPN Tunnels
Instant AP (IAP)has the ability to terminate VPN tunnels on controllers. The IAP cluster creates a tunnel from
the Virtual Controller to aDell mobility controller in your corporate office. The controller only acts as a VPN end-
point and does not configure the IAP. For more information on how to create a VPN tunnel from Virtual
Controller to aDell mobility controller, see Dell Networking W-Series Instant Access Point User Guide.
Termination of IAP GRE Tunnels
IAPs have the ability to terminate GRE tunnels on controllers. The IAP cluster creates a tunnel from the Virtual
Controller to the mobility controller in your corporate office. The controller only acts as a GRE end-point and
does not configure the IAP. For more information on how to create a GRE tunnel from Virtual Controller to the
mobility controller, see the Dell Networking W-Series Instant Access Point User Guide.