Showing results for 
Search instead for 
Did you mean: 

VPN between 2 office with one ZD

New Contributor II
Im going to set up a site-to-site vpn between two offices that we have.
Is there any best practice how to arrange this?

Im need the APs on office 2 to be managed by the ZD in office 1
Is it possible to change that all WLAN users in office 2 will get IP from office1:s DHCP server ?

DHCP server
Ruckus Zonedirector ZD3025
Ruckus 7363 AP

Office 2
Ruckus 7363 AP

New Contributor III
Hi Emil,

DHCP is not routable by default, and DHCP is always a broadcast packets. so the the DHCP request will be dropped in office 2's Router by default.

If you enable DHCP Relay agent in the router's then the Broadcast packets which are received in the routers are converted into uni-cast and directed to the DHCP server in office 1.

So the clients /AP in office 2 can use the same DHCP services which is available in office 1.

I hope this is helpful.

New Contributor II
Thanks for the reply.

Will the ZD in office 1 find the APs in office2 with out any problems?
Do we need to open any specific ports to make this work when using a VPN tunnel?

New Contributor III
Emil, you have to make sure if AP is crossing L3 boundaries then you need to fix the ZD IP in AP via CLI using below command so AP will find the ZD for sure.

set director ip primaryip secondaryip

Example: set director ip
take a look at this KB article - for more info

About ports: you need to have LWAPP UDP ports open on your firewall/router.
Also ensure that latency of your VPN is less than 100ms.

New Contributor III
To answer your original question:

Is it possible to change that all WLAN users in office 2 will get IP from office1:s DHCP server ?

I think it is doable if VLAN id is tagged to WLAN which is being broadcasted at office 2 and WLAN Tunnel mode are used.

How to enable tunnel mode on WLAN --

ZD GUI --> WLAN --> configure --> SSID--> advanced options

Hope it helps.