Users Guide

Table Of Contents
Dell PowerConnect W-Series ArubaOS 6.1 | User Guide Remote Access Points | 187
e. Click Done.
13. Click Apply.
Configure VPN authentication using the internal database
1. Navigate to the Configuration > Security > Authentication > L3 Authentication page.
2. In the Profiles list, select VPN Authentication Profile.
3. For Default Role, enter the user role you created previously (for example, rap_role).
4. Click Apply.
5. In the Profile list, under VPN Authentication Profile, select Server Group.
6. Select the internal server group from the drop-down menu.
7. Click Apply.
Add the user to the internal database
1. Navigate to the Configuration > Security > Authentication > Servers page.
2. Select Internal DB.
3. Click Add User in the Users section. The user configuration page displays.
4. Enter the user name and password.
5. Click Enabled to activate this entry on creation.
6. Click Apply to apply the configuration. Note that the configuration does not take effect until you perform this
step.
7. At the Servers page, click Apply.
Using CLI to configure the internal DB for a RAP user
ip access-list session rap_policy
any any svc-papi permit
any any svc-l2tp permit
any any svc-gre permit
any any svc-esp permit
any any svc-tftp permit
any any svc-ftp permit
user-role rap_role
session-acl rap_policy
Configure VPN authentication using the internal database:
aaa authentication vpn
default-role rap_role
server-group internal
Add the user to the internal database:
local-userdb add username rapuser1 password <password>
Provision the AP
You need to configure the VPN client settings on the AP to instruct the AP to use IPSec to connect to the
controller. You can provision the remote AP and give it to users and allow remote users to provision AP at their
home. See Appendix H, “Provisioning RAP at Home” for more information about provisioning remote AP at
home.
You must provision the AP before you install it at its remote location. To provision the AP, the AP must be
physically connected to the local network or directly connected to the controller. When connected and powered