Users Guide

Table Of Contents
354 | Virtual Private Networks Dell PowerConnect ArubaOS 5.0 | [User Guide
Configure the L2TP/IPsec VPN via the WebUI
Use the following procedure the configure L2TP/IPsec VPN for username/password clients via the WebUI:
1. Navigate to the Configuration > Security > Access Control > Policies page.
2. Click Add to add a new policy.
a. Enter the name of the policy (for example, authenticated). Default settings for a policy rule permit all
traffic from any source to any destination, but you can make a rule more restrictive. You can also configure
multiple rules; the first rule in a policy that matches the traffic is applied.
b. Click Add to add a rule.
c. When you are done adding rules, click Apply.
d. Click the User Roles tab. Click Add to add a new user role.
e. Enter the name of the role (for example, employee).
f. Under Firewall Policies, click Add. In the Choose from Configured Policies drop-down list, select the
policy you previously created. Click Done.
g. Click Apply.
3. Navigate to the Configuration > Security > Authentication > Servers page.
a. Select Internal DB to display entries for the internal database.
b. Click Add User.
c. Enter the username and password.
d. Click Apply.
4. Navigate to the Configuration > Security > Authentication > L3 Authentication page.
a. Select default VPN Authentication Profile.
b. From the Default Role drop-down menu, select employee.
c. Click Apply.
d. Under default VPN Authentication Profile, select Server Group.
e. Select the internal server group from the drop-down menu.
f. Click Apply.
5. Navigate to the Configuration > Advanced Services > VPN Services > IPSEC page.
a. Select Enable L2TP (this is enabled by default).
b. Select PAP for Authentication Protocols.
c. Configure the IP addresses of the primary and secondary Domain Name System (DNS) servers and
primary and secondary Windows Internet Naming Service (WINS) Server that will be pushed to the VPN
client.
d. Under Address Pools, click Add to open the Add Address Pool page.
e. Specify the start address, the end address and the pool name.
f. Click Done to apply the configuration.
g. Under IKE Shared Secrets, click Add to open the Add IKE Secret page.
h. To make the IKE key global, specify 0.0.0.0 and 0.0.0.0 for both subnet and subnet mask (these are the
default values).
i. Enter the IKE Shared Secret and Verify IKE Shared Secret.
j. Click Done to apply the configurations.
k. Under IKE Policies, click Add to open the IPSEC Add Policy configuration page.
l. Set the Priority to 1 for this configuration to take priority over the Default setting.