Configuring IPsec VPN Tunnel
An IPsecInternet Protocol security. IPsec is a protocol suite for secure IP communications that authenticates and encrypts each IP packet in a communication session. tunnel is configured to ensure that the data flow between the networks is encrypted. When configured, the IPsec tunnel to the controller secures corporate data. You can configure an IPsec tunnel from virtual controller using Aruba Central.
To configure an IPsec tunnel from virtual controller, complete the following steps:
1. In the app, set the filter to a group that contains at least one AP.
The dashboard context for the group is displayed.
2. Under , click > .
A list of access points is displayed in the
view.3. Click the icon.
The tabs to configure the access points are displayed.
4. Click , and click the tab.
5. Click the accordion.
6. In the Protocol drop-down list, select Aruba IPsec.
7. In the Primary host field, enter the IP address or FQDNFully Qualified Domain Name. FQDN is a complete domain name that identifies a computer or host on the Internet. for the main VPN/IPsec endpoint.
8. In the Backup host field, enter the IP address or FQDN for the backup VPN/IPsec endpoint. This entry is optional. When you enter the primary host IP address and backup host IP address, other fields are displayed.
9. Specify the following parameters.
a. To allow the VPN tunnel to switch back to the primary host when it becomes available again, select the Preemption check-box. This step is optional. If Preemption is enabled, specify a value in seconds for . When preemption is enabled and the primary host comes up, the VPN tunnel switches to the primary host after the specified hold-time. The default value for is 600 seconds.
b. To allow the Instant AP to create a backup VPN tunnel to the controller along with the primary tunnel, and maintain both the primary and backup tunnels separately, select the check-box. When fast failover is enabled and if the primary tunnel fails, the Instant AP can switch the data stream to the backup tunnel. This reduces the total failover time to less than one minute.
c. Specify a value in seconds for . Based on the configured frequency, the Instant AP can verify if an active VPN connection is available. The default value is 5 seconds, which means that the Instant AP sends one packet to the controller every 5 seconds.
d. Enter a value for , to define a number for lost packets, after which the Instant AP can determine that the VPN connection is unavailable. The default value is 2.
e. To disconnect all wired and wireless users when the system switches during VPN tunnel transition from primary to backup and backup to primary, select the check-box.
f. To configure an interval for which wired and wireless users are disconnected during a VPN tunnel switch, specify a value in seconds for within a range of 30-900 seconds. By default, the reconnection duration is set to 60 seconds. The field is displayed only when is enabled.
10. When the IPsec tunnel configuration is completed, the packets that are sent from and received by an Instant AP are encrypted.
11. Click .
You will be unable to upload the self-signed certificate from Aruba Central. You must upload the self-signed certificate to Aruba ActivateAruba Activate is a cloud-based service that helps provision your Aruba devices and maintain your inventory. Activate automates the provisioning process, allowing a single IT technician to easily and rapidly deploy devices throughout a distributed enterprise network. followed by the AP reboot procedure. When the AP contacts Aruba Activate, the Aruba Activate informs the AP about the self-signed AP certificate that is required to be downloaded. The AP then installs a new certificate before connecting to Aruba Central. For more information, see Aruba Activate User Guide.