vpn tunnel-profile

vpn tunnel-profile

primary

backup

fast-failover

gre-ouitside

hold-time

monitor-pkt-lost-cnt

monitor-pkt-send-freq

per-ap-tunnel

preemption

preemption absolute-time

primary

probe-ip

use custom-cert

no..

Description

This command is used to configure a VPN tunnel profile. The profile created can be associated to an SSID profile.

Parameter

Description

vpn tunnel-profile

Creates a VPN tunnel profile.

backup

Configures an FQDN for the secondary VPN or IPsec endpoint.

fast-failover

Enables fast failover feature for VPN connections.

hold-time

Configures a time period in seconds after which the Instant APs can switch to primary VPN server.

monitor-pkt-lost-cnt

Defines the number of lost packets for VPN connection test or monitoring by theInstant AP.

Default:2

monitor-pkt-send-freq

Configures a frequency interval in seconds at which the test packets are sent.

Default:5

preemption

Enables preemption to allow the VPN tunnel to switch to the primary VPN server when it becomes available after a failover.

preemption absolute-time

Configures a schedule during which theInstant APcan switch from the backup VPN tunnel to the primary VPN tunnel. Associate a time range profile to this parameter for the schedule to take effect.

If absolute time is not configured, the preemption will occur based on thevpn hold-timesettings. When bothvpn hold-timeandpreemption absolute-timeare configured, the preemption will occur at thepreemption absolute-timeschedule.

primary

Configures a FQDN for the main VPN or IPsec endpoint.

probe-ip

Configures an IP address or hostname used to probe connections when VIG is enabled.

gre-ouitside

This command enables automatic configuration of the GRE tunnel between theInstant APand thecontroller.

per-ap-tunnel

This command configures a per ap GRE tunnel.

use custom-cert

Configures an IPsec tunnel to use a customized certificate.

no...

Removes the parameters configured under thevpn tunnel-profilecommand.

Example

The following example configures a non-default VPN tunnel profile:

(Instant AP)(config)# vpn tunnel-profile

(即时美联社)(VPN隧道简介< profile_name >) #primary

(即时美联社)(VPN隧道简介< profile_name >) #backup

(即时美联社)(VPN隧道简介< profile_name >) #fast-failover

(即时美联社)(VPN隧道简介< profile_name >) #hold-time

(即时美联社)(VPN隧道简介< profile_name >) #preemption

(即时美联社)(VPN隧道简介< profile_name >) #monitor-pkt-send-freq

(即时美联社)(VPN隧道简介< profile_name >) #monitor-pkt-lost-cnt

(即时美联社)(VPN隧道简介< profile_name >) #end

(Instant AP)# commit apply

Related Commands

Command

Description

time-range

Creates a time range profile forpreemption absolute-timesetting.

Command History

Release

Modification

Aruba Instant8.10.0.0

Theprobe-ip parameter was added.

Aruba Instant8.9.0.0

A new parameter,absolute-time, to configure a schedule for vpn preemption was added.

ArubaInstant8.4.0.0

Command introduced.

Command Information

Platform

Command Mode

All platforms

Configuration mode