380
Figure 150 Network diagram
Table 16 Interface and IP address assignment
Device Interface IP address Device Interface IP address
Hub 1 GE2/0/1 1.0.0.1/24 Spoke 1 GE2/0/1 1.0.0.4/24
Tunnel1 192.168.1.1/24 GE2/0/2 192.168.10.1/24
Tunnel2 192.168.0.1/24 Tunnel1 192.168.1.3/24
Hub 2 GE2/0/1 1.0.0.2/24 Spoke 2 GE2/0/1 1.0.0.5/24
Tunnel1 192.168.1.2/24 GE2/0/2 192.168.20.1/24
Tunnel2 192.168.0.2/24 GE2/0/3 192.168.30.1/24
Hub 3 GE2/0/1 1.0.0.3/24 Tunnel1 192.168.1.4/24
Tunnel1 192.168.2.1/24 Spoke 3 GE2/0/1 1.0.0.6/24
Tunnel2 192.168.0.3/24 GE2/0/2 192.168.40.1/24
AAA server 1.0.0.10/24 Tunnel1 192.168.2.2/24
Primary server GE2/0/1 1.0.0.11/24 Spoke 4 GE2/0/1 1.0.0.7/24
Secondary server GE2/0/1 1.0.0.12/24 GE2/0/2 192.168.50.1/24
GE2/0/3 192.168.60.1/24
Tunnel1 192.168.2.3/24
Configuring the primary VAM server
1. Configure IP addresses for the interfaces. (Details not shown.)
2. Configure AAA:
AAA server
Hub3
Hub1
Group 1
Group 2
Group 0
Spoke1
Spoke4
Hub2
Tunnel 1
Tunnel 1
Tunnel 1
Tunnel 1
Tunnel 1
Tunnel 1
Spoke2
Spoke3
GE2/0/1
GE2/0/2
GE2/0/1
GE2/0/2
GE2/0/3
GE2/0/1
GE2/0/2
GE2/0/3
GE2/0/1
GE2/0/1
GE2/0/1
GE2/0/1
Tunnel 1
GE2/0/2
Tunnel 2
Tunnel 2
Tunnel 2
Site 1
Site 2 Site 3 Site 4
Site 5
Site 6
Primary server
Secondary server
GE2/0/1
GE2/0/1
Spoke-to-Spoke dynamic tunnel
between two groups
Hub-to-Hub static tunnel
Hub-to-Spoke static tunnel
Spoke-to-Spoke dynamic
tunnel in one group