Users Guide

Table Of Contents
154 | Remote Access Points Dell PowerConnect ArubaOS 5.0 | User Guide
Figure 24 Remote AP with Controller on Public Network
z Deployment Scenario 3: The remote AP is on the public network or behind a NAT device and the controller is
also behind a NAT device. (Dell recommends this deployment for remote access.) The remote AP must be
configured with the tunnel termination point which must be a publicly-routable IP address. In this scenario,
the remote AP uses the public IP address of the corporate firewall. The firewall forwards traffic to an existing
interface on the controller. (The firewall must be configured to pass NAT-T traffic (UDP port 4500) to the
controller.)
Figure 25 Remote AP with Controller Behind Firewall
In any of the described deployment scenarios, the IPSec VPN tunnel can be terminated on a local controller, with
a master controller located elsewhere in the corporate network (Figure 26). The remote AP must be able to
communicate with the master controller after the IPSec tunnel is established. Make sure that the L2TP IP pool
configured on the local controller (from which the remote AP obtains its address) is reachable in the network by
the master controller.
Figure 26 Remote AP in a Multi-Controller Environment
Configuring the Secure Remote Access Point Service
The tasks for configuring an Access Points as a Secure Remote Access Point Service are:
z Configure a public IP address for the controller.
You must install one or more AP licenses in the controller. There are several AP licenses available that support
different maximum numbers of APs. The licenses are cumulative; each additional license installed increases
the maximum number of APs supported by the controller.
z Configure the VPN server on the controller. The remote AP will be a VPN client to the server.
z Configure the remote AP user role.
User roles and policies require the Policy Enforcement Firewall Next Generation (PEFNG) license. To
configure and assign specific user roles you must install the Policy Enforcement Firewall Virtual Private
Network (PEFV) license The example in this section configures a custom user role and policy. You must
Corporate Network
Internet
Controller’s
IP Address
Corporate Network
Internet
Firewall’s
IP Address
Corporate Network
Internet
Firewall’s
IP Address
Local Controller Master Controller