Reference Guide

Table Of Contents
1219 | wlan virtual-ap Dell PowerConnect ArubaOS 6.0 Command Line Interface | Reference Guide
forward-mode
Controls whether 802.11 frames are tunneled to the
controller using generic routing encapsulation (GRE),
bridged into the local Ethernet LAN (for remote APs), or a
combination thereof depending on the destination
(corporate traffic goes to the controller, and Internet
access remains local).
Select one of the following forward modes:
z Tunnel: When an AP is in tunnel forwarding mode, the
AP handles all 802.11 association requests and
responses. The AP sends all 802.11 data packets, action
frames and EAPOL frames over a GRE tunnel to the
controller for processing. The controller removes or
adds the GRE headers, decrypts or encrypts 802.11
frames and applies firewall rules to the user traffic as
usual.
z Bridge: When an AP is in bridge mode, data is bridged
onto the local Ethernet LAN. When in bridge mode, the
AP handles all 802.11 association requests and
responses, encryption/decryption processes, and
firewall enforcement. 802.11e and 802.11k action frames
are also processed by the AP, which then sends out
responses as needed. An AP in bridge mode supports
only the 802.1x authentication type.
z Split-Tunnel: Data frames are either tunneled or
bridged, depending on the destination (corporate traffic
goes to the controller, and Internet access remains
local). The AP handles all 802.11 association requests
and responses, encryption/decryption, and firewall
enforcement. 802.11e and 802.11k action frames are
also processed by the AP, which then sends out
responses as needed. An AP in split-tunnel mode
supports only the 802.1x authentication type.
z Decrypt-Tunnel: An AP in decrypt-tunnel forwarding
mode decrypts and decapsulates all 802.11 frames from
a station and sends the 802.3 frames through the GRE
tunnel to the controller, which then applies firewall
policies to the user traffic. This mode allows a network
to utilize the encryption/decryption capacity the AP
while reducing the demand for processing resources
on the controller. APs in decrypt-tunnel forwarding
mode also manage all 802.11 association requests and
responses, and process all 802.11e and 802.11k action
frames.
NOTE: Virtual APs in bridge or split-tunnel mode using static
WEP should use key slots 2-4 on the controller . Key slot 1
should only be used with Virtual APs in tunnel mode.
tunnel
bridge
split-tunnel
decrypt-tunnel
tunnel
ha-disc-onassoc
If enabled, all clients of a virtual-ap will receive mobility
service on association.
—disabled
mobile-ip
Enables or disables IP mobility for this virtual AP. enabled
multi-association
Enables or disables multi-association for this virtual AP.
When enabled, this feature allows a station to be
associated to multiple APs. If this feature is disabled, when
a station moves to new AP it will be de authorized by the AP
to which it was previously connected, deleting station
context and flushing key caching information.
—disabled
no
Negates any configured parameter.
Parameter Description Range Default