Administrator Guide

Table Of Contents
414 | Virtual Private Networks Dell Networking W-Series ArubaOS 6.4.x| User Guide
VPN Client RAP psk RAP certs CAP
External AAA server 1 LocalDB LocalDB-AP CPSEC-whitelist
External AAA server 1 External AAA server 1 Not supported CPSEC-whitelist
External AAA server 1 External AAA server 2 Not supported CPSEC-whitelist
LocalDB LocalDB LocalDB-AP CPSEC-whitelist
LocalDB External AAA server 1 Not supported CPSEC-whitelist
Table 79: Supported VPN AAA Deployments
Working with Certificate Groups
The certificate group feature allows you to access multiple types of certificates on the same controller. To
create a certificate group, use the following command:
(host) (config) #crypto-local isakmp certificate-group server-certificate server_certificate
ca-certificate ca_certificate
You can view existing certificate groups using:
show crypto-local isakmp certificate-group
Working with VPN Authentication Profiles
VPN Authentication profiles identify an authentication server, the server group to which the authentication
server belongs, and a user-role for authenticated VPN clients. There are three predefined VPN authentication
profiles: default, default-rap, and default-cap. These different profiles allow you to use different
authentication servers, user roles, and IP pools for VPN, remote AP, and campus AP clients.
You can configure the default and default-rap profiles, but not the default-cap profile.