418
Figure 153 Network diagram
Table 17 Interface and IP address assignment
Device Interface IP address Device Interface IP address
Hub 1 GE2/0/1 1::1/64 Spoke 1 GE2/0/1 1::4/64
Tunnel1 192:168:1::1/64 GE2/0/2 192:168:10::1/64
Tunnel2 192:168::1/64 Tunnel1 192:168:1::3/64
Hub 2 GE2/0/1 1::2/64 Spoke 2 GE2/0/1 1::5/64
Tunnel1 192:168:1::2/64 GE2/0/2 192:168:20::1/64
Tunnel2 192:168::2/64 GE2/0/3 192:168:30::1/64
Hub 3 GE2/0/1 1::3/64 Tunnel1 192:168:1::4/64
Tunnel1 192:168:2::1/64 Spoke 3 GE2/0/1 1::6/64
Tunnel2 192:168::3/64 GE2/0/2 192:168:40::1/64
AAA server 1::10/64 Tunnel1 192:168:2::2/64
Primary server GE2/0/1 1::11/64 Spoke 4 GE2/0/1 1::7/64
Secondary server GE2/0/1 1::12/64 GE2/0/2 192:168:50::1/64
GE2/0/3 192:168:60::1/64
Tunnel1 192:168:2::3/64
Configuring the primary VAM server
1. Configure IP addresses for the interfaces. (Details not shown.)
2. Configure AAA:
AAA server
Hub3
Hub1
Group 1
Group 2
Group 0
Spoke1
Spoke4
Hub2
Tunnel 1
Tunnel 1
Tunnel 1
Tunnel 1
Tunnel 1
Tunnel 1
Spoke2
Spoke3
GE2/0/1
GE2/0/2
GE2/0/1
GE2/0/2
GE2/0/3
GE2/0/1
GE2/0/2
GE2/0/3
GE2/0/1
GE2/0/1
GE2/0/1
GE2/0/1
Tunnel 1
GE2/0/2
Tunnel 2
Tunnel 2
Tunnel 2
Site 1
Site 2 Site 3 Site 4
Site 5
Site 6
Primary server
Secondary server
GE2/0/1
GE2/0/1
Spoke-to-Spoke dynamic tunnel
between two groups
Hub-to-Hub static tunnel
Hub-to-Spoke static tunnel
Spoke-to-Spoke dynamic
tunnel in one group