
AOS-W Instant 6.3.1.1-4.0 | User Guide IAP-VPN Configuration | 252
Chapter 23
IAP-VPN Configuration
Alcatel-Lucent switches provide an ability to terminate the IPSec and GRE VPNtunnels from the OAW-IAP and
provide corporate connectivity to the branch network.
This section describes the following topics:
l Overview on page 252
l VPN Configuration on page 255
l Viewing Branch Status on page 256
Overview
This section provides a brief summary of the features supported by the switches to allow VPN termination from an
OAW-IAP.
Termination of IPSec and GRE VPNTunnels
OAW-IAPscan terminate VPN tunnels on Switches. The OAW-IAP cluster creates an IPSec or GRE VPNtunnel
from the Virtual Controller to a OmniAccess WLAN Switch in your corporate office. The switch only acts an IPSec or
GRE VPN end-point and it does not configure the OAW-IAP. For more information on how to create an IPSec or
GREVPN tunnel, see VPN Configuration on page 239.
L2/L3 Forwarding Modes
The Virtual Controller enables different DHCP pools (various assignment modes) in addition to allocating IP subnets
for each branch. The Virtual Controller allows different modes of forwarding of traffic from the clients on a VLAN with
a VPN tunnel. The forwarding modes are associated with various modes of DHCP address assignment modes. For
more information on DHCP assignment modes and configuring DHCP scope for IAP-VPN, see Configuring DHCP
Scopes on page 231.
The following DHCP modes are supported:
l NAT Mode: In this mode, the source IP for all client traffic is translated. The traffic destined for the corporate
network is translated using the VPN tunnel IP address of the OAW-IAP and is forwarded through the IPsec VPN
tunnel. The traffic destined for the non-corporate network is translated using the IP address of the IAP and is
forwarded through the uplink.
When the NAT mode is used for forwarding client traffic, hosts on the corporate network cannot establish
connections to the clients on the OAW-IAP, because the source address of the clients is translated.
l L2 Switching Mode: In this mode, the traffic destined for the corporate network is bridged through the VPN
tunnel to the Switch and the destined for the non-corporate network is translated using the IP address of the
OAW-IAP and is forwarded through the uplink.
When an OAW-IAP registers with the Switch, and is configured to use the L2 DHCP address assignment mode,
the Switch automatically adds the VPN tunnel associated to this OAW-IAP into the VLAN multicast table. This
allows the clients connecting to the L2 mode VLAN to be part of the same L2 broadcast domain on the Switch.
l L3 Routing Mode: In this mode, the traffic destined for the corporate network is routed through the VPN tunnel to
the Switch and the traffic destined for the non corporate network is translated using the IP address of the OAW-
IAP and is forwarded through the uplink.
When an OAW-IAP registers with the Switch and is configured to use the L3 DHCP address assignment mode,
the Mobility Switch adds a route on the Switch, enabling routing of traffic from the corporate network to clients on
this subnet in the branch.
Kommentare zu diesen Handbüchern