AP Based DHCP or NAT
In highly distributed environments, particularly those with only a few APs per site, the ability for an AP or a set of APs to provide DHCP or NAT support to local client devices simplifies deployment by providing all-in-one functionality on the AP, which eliminates the need for a separate router and DHCP server for each site. It also eases site management by providing central control and monitoring of the distributed APs and their clients.
Three general DHCP scenarios are supported:
- SMB Single AP: DHCP is running on a single AP only. This AP also functions as the Gateway AP.
- SMB Multiple APs (<12): DHCP service is running on all APs, among which two of the APs will be Gateway APs. These two Gateway APs will provide the IP addresses as well as Internet connectivity to the clients through NAT.
- Enterprise (>12): For Enterprise sites, an additional on site vSZ-D will be deployed at the remote site which will assume the responsibilities of performing DHCP or NAT functions. Therefore, DHCP or NAT service will not be running on any APs (they will serve clients only), while the DHCP or NAT services are provided by the onsite vSZ-D.
Profile Based DHCP
The DHCP Server is designed in-line in the data plane and provides extreme scale in terms of IP address assignment to clients. This feature is especially useful in high density and dynamic deployments like stadiums, train stations where large number of clients continuously move in and out of Wi-Fi coverage. The DHCP server in the network needs to scale to meet these challenging requirements. The DHCP server on the vSZ-D provides high scale IP address assignment and management with minimal impact on forwarding latency. The DHCP server allows IP address assignment only when a DHCP license assignment policy is created for a specific vSZ-D. A maximum of 101k IP address assignments are allowed for each vSZ-D. Additional IP address assignments require additional licensing.
Profile-based NAT
With NAT service enabled, all the Wi-FI client traffic is NAT routed by the vSZ-D before forwarding to the core network. The NAT license assignment policy for the specific vSZ-D must be created. Each vSZ-D supports up to 2 million NAT ports (traffic sessions) and 128 public IP addresses for NAT. This feature reduces the network overhead significantly since it reduces the MAC-table considerations on the UP-stream switches significantly. This feature is very useful in high density deployments.