Migrate to Tunnel Concentrator using Classification Rules

Use this procedure to migrate a VGVA identity-based tunneling deployment that is managed by ExtremeCloud IQ to Tunnel Concentrator using classification rules. This migration method does not require a new Network Policy.
  1. Configure classification rules for the Network Policy:
    1. On ExtremeCloud IQ (Classic), go to Configure > Common Objects > Policy > Classification Rules.
    2. Create two classification rules and configure classification categories for each that specify which APs and sites to migrate during phase 1 of the migration:
      • Rule 1 contains existing VGVA tunneling settings (for example, VGVA) and applies to the sites that remain under current settings for Phase 1.

      • Rule 2 contains Tunnel Concentrator settings (for example, Tunnel Concentrator) and applies to sites and APs that you want to migrate during Phase 1.

  2. Clone the SSIDs that you want to migrate:
    1. Go to Configure > Common Objects > Policy > SSID.
    2. Select the SSID that the wireless network uses.
    3. Select (Clone) to create a new SSID based on the existing SSID settings.
    4. For the new SSID, assign a unique SSID Name and Broadcast Name as these fields must have unique names within a single Network Policy.
  3. Clone the default User Profile that the SSID uses:
    1. Go to Configure > Common Objects > Policy > User Profiles.
    2. Select the default User Profile that your original SSID uses.
    3. Select (Clone) to create a new User Profile based on settings of the original profile.
    4. In the new User Profile, under Traffic Tunneling, select Tunnel Concentrator.
    5. For Tunnel Destination, select a Tunnel Concentrator.
      Note

      Note

      If you need to create the Tunnel Concentrator, select (+) and complete the configuration. For details, see Configure Tunnel Concentrator Service.
    6. Return to the SSID configuration for the SSID clone that you created in Step 2 and set the default Default User Profile to use the new User Profile clone that you just created.
  4. Assign classification rules to the APs at your sites:
    1. Go to Configure > Network Policy.
    2. Select the existing Network Policy and then select 2 Wireless.
    3. Make sure that the list of SSIDs includes both the existing and cloned SSIDs. If any SSIDs are missing, select (Select icon) and add them.
    4. For each SSID, select and assign the appropriate classification rule to the SSID:
      • Assign the VGVA rule to SSIDs that will remain on existing VGVA settings.

      • Assign the Tunnel Concentrator rule to SSIDs that will migrate to Tunnel Concentrator.

  5. Save all settings and push the new settings to the APs.
    Note

    Note

    • Push new settings to the APs only during a maintenance window.

    • Run the new configuration for a few days to verify the new settings.

  6. After the migration is verified, update the classification rule categories so that all sites and APs that you want to migrate use the Tunnel Concentrator rule and then push those settings to the APs.