Users Guide

Table Of Contents
Dell PowerConnect ArubaOS 5.0 | User Guide Remote Access Points | 161
user-role rap_role
session-acl rap_policy
Configure VPN authentication using the internal database:
aaa authentication vpn
default-role rap_role
server-group internal
Add the user to the internal database:
local-userdb add username rapuser1 password <password>
Provision the AP
You need to configure the VPN client settings on the AP to instruct the AP to use IPSec to connect to the
controller. You can provision the remote AP and give it to users and allow remote users to provision AP at their
home. See Appendix G, “Provisioning RAP at Home” for more information about provisioning remote AP at
home.
You must provision the AP before you install it at its remote location. To provision the AP, the AP must be
physically connected to the local network or directly connected to the controller. When connected and powered
on, the AP must also be able to obtain an IP address from a DHCP server on the local network or from the
controller.
If your configuration has an internal LMS IP address, remote APs may attempt to switch over to the LMS IP
address, which is not reachable from the Internet. For remote APs, ensure that the LMS IP address in the AP
system profile for the AP group has an externally routable IP address.
Reprovisioning the AP causes it to automatically reboot. The easiest way to provision an AP is to use the
Provisioning page in the WebUI, as described in the following steps:
1. Navigate to the Configuration > Wireless > AP Installation > Provisioning page. Select the remote AP and
click Provision.
2. Under Authentication Method, select IPSec Parameters. Enter the Internet Key Exchange (IKE) Pre-Shared
Key (PSK), username, and password.
3. Under Master Discovery, set the Master IP Address as shown below:
4. Under IP Settings, make sure that Obtain IP Address Using DHCP is selected.
5. Click Apply and Reboot.
Note: The username and password you enter must match the username and password configured on the authentication server for
the remote AP
Deployment Scenario Master IP Address Value
Deployment 1 Controller IP address
Deployment 2 Controller public IP address
Deployment 3 Public address of the NAT device to which the controller is connected
Note: The username and password you enter must match the username and password configured on the authentication server for
the remote AP