Aruba SD-Branch provides flexible deployment options for the WAN and LAN. This guide will detail the default hub-and-spoke WAN topology and an L2 LAN topology, though other topologies will be mentioned. This deployment will consist of three remote sites and a single headend Data Center.
Each remote site will have redundant branch gateways providing both circuit termination and LAN default gateway. Switches at branch sites will provide L2 connectivity for the APs and other client devices. It is best practice to standardize on the same branch design for all sites to realize the full benefits of Central configuration. Multiple branch designs can be accommodated and will be addressed in the Preparing to Deploy section.
A pair of VPNCs (VPN concentrators) will be the configured to facilitate connectivity between the campus network and branch sites via IPSEC tunnels and route sharing. VPNCs will summarize the campus subnets to a single route of 10.0.X.X/13 and prevent point-to-point links from being advertised to the branches. Below is the VLAN layout and IP information that will be configured on each of the VPNC pairs.
VPNC VLANS
Gateway Pool
INET
MPLS
MicroBranch
OSPF_Link_1
OSPF_Link_2
VLAN ID
4085
4094
4086
101
4001
4002
7210-VPNC-DC1-1
Gateway Pool
INET
MPLS
MicroBranch
OSPF_Link_1
OSPF_Link_2
IP Address
DHCP
X.X.X.X
172.17.1.26
10.8.0.2
172.18.106.22
172.18.106.30
7210-VPNC-DC1-2
Gateway Pool
INET
MPLS
MicroBranch
OSPF_Link_1
OSPF_Link_2
IP Address
DHCP
X.X.X.X
172.17.1.22
10.8.0.3
172.18.106.18
172.18.106.26
Each remote site will consist of two branch gateways, two switches, and three access points. Each branch site will be assigned a /21 subnet from the superset address space of 10.14.X.X/16. Within the 10.14.X.X/16 address space, two subnets will be reserved. 10.14.255.X/24 will be reserved for the branch gateway pool, and 10.14.254.X/24 for Microbranch system IP’s. The VPNCs will advertise a summary network of 10.14.X.X/16. Branch switches at each site will have nine VLANs. Their default gateways is a virtual IP shared between the branch gateways at each site. The other three VLANs (Gateway pool, INET, MPLS) will only exist on the Branch gateways. Switches and access points will receive an IP address on the MGMT VLAN.