Users Guide

Table Of Contents
1075 | Instant AP VPN Support Dell Networking W-Series ArubaOS 6.4.x| User Guide
l L2 Switching Mode: In this mode, Instant supports distributed L2 and centralized L2 switching modes of
connection to corporate. When an Instant AP registers with the controller and has a L2 mode DHCP pool
configured, the controller automatically adds the GRE or VPN tunnel associated to this IAP into the VLAN
multicast table. This allows the clients connecting to this L2 mode VLAN to be part of the same L2 domain
on controller.
l L3 Routing Mode: In this mode, Instant supports L3 routing mode of connection to corporate. The VC
assigns an IP addresses from the configured subnet and forwards traffic to both corporate and non-
corporate destinations. Instant AP takes care of routing on the subnet and also adds a route on the
controller after the VPN tunnel is set up during the registration of the subnet. When the Instant AP registers
with a L3 mode DHCP pool, the controller automatically adds a route to this DHCP subnet enabling routing
of traffic from the corporate to clients on this VLAN in the branch.
Instant AP VPN Scalability Limits
ArubaOS provides enhancements to the scalability limits for the IAP VPN branches terminating on the
controller. The following table provides the IAP VPN scalability information for various controller platforms:
Table 239: Instant AP VPN Scalability Limits
Platforms Branches Routes L3 Mode Users NATUsers Total L2 Users
W-3200 1000 1000 N/A N/A 64000
W-3400 2000 2000 64000
W-3600 8000 8000 64000
W-6000M3 8000 8000 64000
W-7210 8000 8000 64000
W-7220 16000 16000 128000
W-7240 32000 32000 128000
l Branches—The number of IAP VPN branches that can be terminated on a given controller platform.
l Routes—The number of L3 routes supported on the controller.
l L3 mode and NAT mode users—The number of trusted users supported on the controller. There is no
scale impact on the controller. They are limited only by the number of clients supported per Instant AP.
l L2 mode users—The number of L2 mode users are limited to128000 for W-7220 and W-7240 and 64000
across all other platforms.
Instant AP VPN OSPF Scaling
ArubaOS allows each IAP VPN to define a separate subnet derived from a corporate intranet pool to allow IAP
VPN devices to work independently. For information on sample topology and configuration, see OSPFv2.
To redistribute IAP VPN routes into the OSPF proces, use the following command :
(host)(config) # router ospf redistribute rapng-vpn
To verify if the redistribution of the IAP VPN is enabled, use following command:
(host) #show ip ospf redistribute