Cloud Managed Networks

 View Only
  • 1.  AOS10 - Cluster of 3+ Gateways - None "Default gateway mode"

    Posted Jul 15, 2025 08:17 AM

    looking for documentation which covers the following topics,  

    1. VSG for active-active cluster which allow to load share of users between gateways in the AOS10 cluster.

    2. information about cluster behavior in none "default gateway mode".

    3. what is the purpose for setting different virtual ip address for etch gateway in the cluster.

    4.how to setup the dhcp for the clients and when we should add more than one gateway in the dhcp offer. 

    "Multiple Default Routers should be separated by spaces"

    Thanks,

    Me



  • 2.  RE: AOS10 - Cluster of 3+ Gateways - None "Default gateway mode"

    Posted Jul 15, 2025 09:25 AM

    I am not sure if you got a chance to check out the VSG site https://arubanetworking.hpe.com/techdocs/VSG/docs/020-campus-deploy/esp-campus-deploy-030-campus-network-overview/

    I general when Tunnelling traffic to a GW-cluster, you would trunk all the client vlans down to a Core/DC or where ever you would like to drop the client traffic. The client vlan GW will exist at the core/DC point while you will have a SVI per GW for example ( client vlan 100, core-192.168.100.1, gw1- 19.168.100.2, gw2- 192.168.100.3).

    You would put the DHCP pools on your DHCP-server and put your IP-helper on the Core/DC that has the client vlan gateways in this care 192.168.100.1 vlan interface.




  • 3.  RE: AOS10 - Cluster of 3+ Gateways - None "Default gateway mode"

    Posted Jul 15, 2025 10:25 AM

    thank you for replying, I actually saw this document and it doesn't cover the topics I referred to.

    in our case the gateways are the layer3, dhcp service and routers for that network, there is no DC or Core and we have multiple wan assigned to them.

    attaching screenshots from the central ui.

    i would like to get clarification on the following subjects, 

    2. I need information about cluster behavior in none "default gateway mode".

    3. what is the purpose for setting different virtual ip address for etch gateway in the cluster.

    for example, 

    gateway 1

    vlan 10, SVI ip address 192.168.10.1

    vlan 10, Cluster virtual ip address 192.168.10.251

    gateway 2

    vlan 10, SVI ip address 192.168.10.2

    vlan 10, Cluster virtual ip address 192.168.10.252

    gateway 3

    vlan 10, SVI ip address 192.168.10.3

    vlan 10, Cluster virtual ip address 192.168.10.253

    4.how to setup the dhcp for the clients and when we should add more than one gateway in the dhcp offer. 

    "Multiple Default Routers should be separated by spaces"

    Regards,

    Me




  • 4.  RE: AOS10 - Cluster of 3+ Gateways - None "Default gateway mode"

    Posted Jul 15, 2025 11:14 AM

    Default gateway mode is available when the cluster has two nodes and is there specifically to better support situations where the gateways are being used to provide routing for the internal networks.  This is most used when the gateways are deployed in an SD-Branch solution.  Default gateway mode for a mobility deployment is available with newer software releases but generally only there for when you need a separate network, i.e., guest, and need to support DHCP and HA from the gateways.

    If you're setting up a larger cluster of 3+ nodes then you'll need DHCP to be provided by the network as the DHCP will not be sync'd across nodes when not running in default gateway mode.

    The cluster VIPs are there to provide HA support for dynamic authorization.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 5.  RE: AOS10 - Cluster of 3+ Gateways - None "Default gateway mode"

    Posted Jul 15, 2025 02:19 PM

    Hi Carson, 

    Thank you for replying, gateways use the mgmt interface to communicate with the radius, 

    different virtual ips allowing the radius to preform coa actions when one of the gateways is unreachable.

    still I'm trying to understand the purpose of having different virtual ip in users vlan for what reason this option exist? 

    also, please advise what is the purpose of configuring multiple gateways in the dhcp settings?  this option is available in the latest AOS10.

    it will be highly appreciated to have some documents that cover those options.  

    Regards,

    Me




  • 6.  RE: AOS10 - Cluster of 3+ Gateways - None "Default gateway mode"

    Posted Jul 15, 2025 02:33 PM
    Edited by chulcher Jul 15, 2025 02:34 PM

    If you have the cluster VRRP/VIP configured properly then the cluster nodes will utilize the VIPs for communicating with RADIUS, otherwise they use the system-ip or whatever is configured as the RADIUS source-interface.

    The "different virtual IP in users VLAN" question is likely a misunderstanding of what is going on.  When a default gateway cluster is operational, then each gateway will have an IP address in each VLAN that the gateways are providing routing for and a single VIP will be in place to provide the default gateway failover required for HA.

    You seem to be conflating the presence or possibility for options with necessity.

    If this isn't making sense then I highly recommend a conversation with your account or channel team on what you are trying to accomplish, or perhaps a better explanation here of what you are trying to accomplish.  Based on what you've shared so far, you're attempting a configuration that isn't supported, barely works, or wasn't intended in the first place.  First and foremost, a gateway cluster of 3+ nodes should only ever be used for mobility (WLAN and/or SD-LAN/UBT/PBT) purposes and all network interactions (other than management and dataplane tunneling) should be occurring at layer 2.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------