Aruba SD-Branch provides flexible deployment options for WAN and LAN.
This guide details a hub-and-spoke WAN topology and an L2 LAN topology, with additional comments related to other topologies. This deployment consists of three remote sites and a single headend data center.
Each remote site has redundant branch gateways providing circuit termination and a LAN default gateway. Switches at branch sites provide L2 connectivity for the APs and other client devices. It is best practice to standardize the branch design for all sites to realize the full benefits of Aruba Central configuration. Multiple branch designs can be accommodated, as addressed in the Preparing to Deploy section.
A pair of VPNCs (VPN concentrators) is configured to facilitate connectivity between the campus network and branch sites using IPsec tunnels and route sharing. VPNCs summarize the campus subnets to a single route of 10.0.X.X/13 and prevent advertising point-to-point links to the branches. The VLAN layout and IP information configured on each VPNC in the pair are shown below.
VPNC VLANS
Gateway Pool
INET
MPLS
MicroBranch
OSPF_Link_1
OSPF_Link_2
VLAN ID
2085
2084
2086
101
4001
4002
RSVDC-VPNC1-1
Gateway Pool
INET
MPLS
MicroBranch
OSPF_Link_1
OSPF_Link_2
IP Address
DHCP
X.X.X.X
100.100.7.5
10.8.0.2
172.18.106.22
172.18.106.30
RSVDC-VPNC1-2
Gateway Pool
INET
MPLS
MicroBranch
OSPF_Link_1
OSPF_Link_2
IP Address
DHCP
X.X.X.X
100.100.7.6
10.8.0.3
172.18.106.18
172.18.106.26
Each remote site consists of two branch gateways, two switches, and three access points. Each branch site is assigned a /21 subnet from the superset address space of 10.14.X.X/16. Within the 10.14.X.X/16 address space, two subnets are reserved: 10.14.255.X/24 is reserved for the branch gateway pool, and 10.14.254.X/24 for Microbranch system IPs.
The VPNCs advertise a summary network of 10.14.X.X/16. Branch switches at each site have nine VLANs. Their default gateway is a virtual IP shared among the branch gateways at each site. The other three VLANs (Gateway pool, INET, MPLS) exist only on the branch gateways. Switches and access points receive an IP address on the MGMT VLAN.