
In the CLI
To enable automatic configuration of the GRE tunnel:
(Instant Access Point)(config)# vpn gre-outside
(Instant Access Point)(config)# vpn primary <name/IP-address>
(Instant Access Point)(config)# vpn backup <<name/IP-address>>
(Instant Access Point)(config)# vpn fast-failover
(Instant Access Point)(config)# vpn hold-time <seconds>
(Instant Access Point)(config)# vpn preemption
(Instant Access Point)(config)# vpn monitor-pkt-send-freq <frequency>
(Instant Access Point)(config)# vpn monitor-pkt-lost-cnt <count>
(Instant Access Point)(config)# vpn reconnect-user-on-failover
(Instant Access Point)(config)# vpn reconnect-time-on-failover <down_time>
(Instant Access Point)(config)# end
(Instant Access Point)# commit apply
To view VPN configuration details:
(Instant Access Point)# show vpn config
Manually Configuring a GRETunnel
You can also manually configure a GRE tunnel by configuring the GRE tunnel parameters on the OAW-IAP and
switch. This procedure describes the steps involved in manual configuration of GRE tunnel from Virtual Controller by
using AOS-W Instant UI or CLI.
During the manual GRE setup, you can either use the Virtual Controller IP or the OAW-IAP IP to create the GRE
tunnel at the controller side depending upon the following OAW-IAP settings:
l If a Virtual Controller IP is configured and if Per-AP tunnel is disabled, then the Virtual Controller IP is used to
create the GRE tunnel.
l If a Virtual Controller IP is not configured or if Per-AP tunnel is enabled, then the OAW-IAP IP is used to create
the GRE tunnel.
For information on the GRE tunnel configuration on Switch, see
AOS-W Instant User Guide
.
In the AOS-W Instant UI
1. Click the More>VPN link at the top right corner of the AOS-W Instant UI. The Tunneling window is displayed.
2. Select Manual GRE from the Protocol drop-down list.
3. Specify the following parameters. A sample configuration is shown in Figure 81.
a. Enter the IP address or the FQDN for the main VPN/GRE endpoint.
b. Enter the value for GRE type parameter.
c. Select Enabled or Disabled from the Per-AP tunnel drop-down list. The administrator can enable this option
to create a GRE tunnel from each OAW-IAP to the VPN/GRE Endpoint rather than the tunnels created just
from the master OAW-IAP. When enabled, the traffic to the corporate network is sent through a Layer-2 GRE
tunnel from the OAW-IAP itself and need not be forwarded through the master OAW-IAP.
By default, the Per-AP tunnel option is disabled.
AOS-W Instant 6.3.1.1-4.0 | User Guide VPN Configuration | 243
Comentários a estes Manuais