Ipsec stateful failover configuration example, Network requirements, Configuring ac 1 – H3C Technologies H3C WX3000E Series Wireless Switches User Manual
Page 374
360
IPsec stateful failover configuration example
Network requirements
A company uses ACs and APs to construct its internal network. IPsec and reliability are required between
ACs and APs.
Configure the ACs as follows:
•
Assign the ACs to the VLAN to which the AP belongs.
•
Configure stateful failover between AC 1 and AC 2. The ACs send heartbeat packets to each other
through the switch.
•
Set up an IPsec tunnel between AC 1 and the AP and an IPsec tunnel between AC 2 and the AP, and
set up LWAPP tunnels based on the IPsec tunnels.
Figure 148 Network diagram
Configuring AC 1
# Configure an IP address for VLAN-interface 1.
<AC1> system-view
[AC1] interface Vlan-interface 1
[AC1-Vlan-interface1] ip address 133.1.1.1 16
[AC1-Vlan-interface1] quit
# Enable stateful failover and set the stateful failover heartbeat interval.
[AC1] hot-backup enable
[AC1] hot-backup hellointerval 100
# Set the IKE SA keepalive interval.
[AC1] ike sa keepalive-timer interval 20
# Set the IKE SA keepalive timeout.
[AC1] ike sa keepalive-timer timeout 60
# Enable invalid SPI recovery.
[AC1] ipsec invalid-spi-recovery enable
# Create an IPsec proposal named tran1.
- H3C WX5500E Series Access Controllers H3C WX3500E Series Access Controllers H3C WX2500E Series Access Controllers H3C WX6000 Series Access Controllers H3C WX5000 Series Access Controllers H3C LSWM1WCM10 Access Controller Module H3C LSUM3WCMD0 Access Controller Module H3C LSUM1WCME0 Access Controller Module H3C LSWM1WCM20 Access Controller Module H3C LSQM1WCMB0 Access Controller Module H3C LSRM1WCM2A1 Access Controller Module H3C LSBM1WCM2A0 Access Controller Module H3C WA3600 Series Access Points H3C WA2600 Series WLAN Access Points H3C S10500 Series Switches H3C S5800 Series Switches H3C S5820X Series Switches H3C S12500 Series Switches H3C S9500E Series Switches H3C MSR 5600 H3C MSR 50 H3C MSR 3600 H3C MSR 30 H3C MSR 2600 H3C MSR 20-2X[40] H3C MSR 20-1X H3C MSR 930 H3C MSR 900 H3C SR8800 H3C SR6600-X H3C SR6600 H3C SecPath F5020 H3C SecPath F5040 H3C VMSG VFW1000