Configuring Automatic GRE VPN Tunnel
In Aruba Central (on-premises), you can configure an Instant Access Point (IAP) to automatically set up a GREGeneric Routing Encapsulation. GRE is an IP encapsulation protocol that is used to transport packets over a network. tunnel from the IAP to the controller.
To configure an IAP to automatically set up a GRE tunnel, complete the following steps:
- In the
The dashboard context for the group is displayed.
app, set the filter to a group containing at least one AP. - Under
A list of APs is displayed in the
view.
, click > . - Click the
The tabs to configure the APs are displayed.
icon. - Click .
- Click the tab.
- Click the accordion.
-
In the Protocol drop-down list, select Aruba GRE.
-
In the Primary host field, enter the IP address or FQDNFully Qualified Domain Name. FQDN is a complete domain name that identifies a computer or host on the Internet. for the main VPN/IPsecInternet Protocol security. IPsec is a protocol suite for secure IP communications that authenticates and encrypts each IP packet in a communication session. endpoint.
-
In the Backup host field, enter the IP address or FQDN for the backup VPN/IPsec endpoint. This entry is optional. When you enter the primary host IP address and backup host IP address, other fields are displayed.
-
Specify the following parameters:
- Select the Preemption check-box to allow the VPN tunnel to switch back to the primary host when it becomes available again. This step is optional. If Preemption is enabled, specify a value in seconds for . When preemption is enabled and the primary host comes up, the VPN tunnel switches to the primary host after the specified hold time. The default value for is 600 seconds.
- Select the controller along with the primary tunnel, and maintain both the primary and backup tunnels separately. If the primary tunnel fails, the IAP can switch the data stream to the backup tunnel. This reduces the total failover time to less than one minute. check-box to allow the IAP to create a backup VPN tunnel to the
- Select the to disconnect all wired and wireless users when the system switches during VPN tunnel transition from primary to backup and backup to primary,
- Specify a value in seconds for to configure an interval for which wired and wireless users are disconnected during a VPN tunnel switch. By default, the reconnection duration is set to 60 seconds.
- Specify a value in seconds for . Based on the configured frequency, the IAP can verify if an active VPN connection is available. The default value is 5 seconds, which means that the IAP sends one packet to the controller every 5 seconds.
- Enter a value for to define a number for lost packets, after which the IAP can determine that the VPN connection is unavailable. The default value is 2.
- Select the check-box to create a GRE tunnel from each IAP to the VPN/GRE Endpoint rather than the tunnels created just from the conductor IAP. When enabled, the traffic to the corporate network is sent through a Layer-2 GRE tunnel from the IAP itself and need not be forwarded through the conductor IAP.
- From the drop-down list, select the branch name.
- Click .