Dell PowerConnect W Clearpass 100 Software Guía de usuario Pagina 225

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 296
  • Tabla de contenidos
  • SOLUCIÓN DE PROBLEMAS
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 224
AOS-W Instant 6.2.1.0-3.3| User Guide IAP-VPN Configuration | 225
Chapter 22
IAP-VPN Configuration
Alcatel-Lucent switches provide an ability to terminate the IPSec and GRE VPNtunnels from the OAW-IAP and
provide corporate connectivity to the branch network.
This section describes the following topics:
l Overview on page 225
l VPN Configuration on page 226
l Viewing Branch Status on page 227
Overview
This section provides a brief summary of the features supported by the switches to allow VPN termination from an
OAW-IAP.
Termination of IPSec and GRE VPNTunnels
OAW-IAPscan terminate VPN tunnels on Switch. The IAP cluster creates an IPSec or GRE VPNtunnel from the
Virtual Controller to a Mobility Switch in your corporate office. The switch only acts an IPSec or GRE VPN end-point
and it does not configure the OAW-IAP. For more information on how to create an IPSec or GREVPN tunnel, see
VPN Configuration on page 221.
L2/L3 Forwarding Modes
The Virtual Controller enables different DHCP pools (various assignment modes) in addition to allocating IP subnets
for each branch. The Virtual Controller allows different modes of forwarding of traffic from the clients on a VLAN with
a VPN tunnel. The forwarding modes are associated with various modes of DHCP address assignment modes. For
more information on DHCP assignment modes and configuring DHCP scope for IAP-VPN, see Understanding
DHCP Assignment Modes on page 213.
The following DHCP modes are supported:
l NAT Mode: In this mode, the source IP for all client traffic is translated. The traffic destined for the corporate
network is translated using the VPN tunnel IP address of the OAW-IAP and is forwarded through the IPsec VPN
tunnel. The traffic destined for the non-corporate network is translated using the IP address of the IAP and is
forwarded through the uplink.
When the NAT mode is used for forwarding client traffic, hosts on the corporate network cannot establish
connections to the clients on the OAW-IAP, because the source address of the clients is translated.
l L2 Switching Mode: In this mode, the traffic destined for the corporate network is bridged through the VPN
tunnel to the switch and the destined for the non-corporate network is translated using the IP address of the
OAW-IAP and is forwarded through the uplink.
When an OAW-IAP registers with the switch, and is configured to use the L2 DHCP address assignment mode,
the switch automatically adds the VPN tunnel associated to this OAW-IAP into the VLAN multicast table. This
allows the clients connecting to the L2 mode VLAN to be part of the same L2 broadcast domain on the switch.
l L3 Routing Mode: In this mode, the traffic destined for the corporate network is routed through the VPN tunnel to
the switch and the traffic destined for the non corporate network is translated using the IP address of the OAW-
IAP and is forwarded through the uplink.
Vista de pagina 224
1 2 ... 220 221 222 223 224 225 226 227 228 229 230 ... 295 296

Comentarios a estos manuales

Sin comentarios