Administrator Guide

Table Of Contents
a. Specify which AP group or AP to which the virtual AP profile applies.
b. set the VLAN used for split tunneling. Only one VLAN can be configured for split tunneling; VLAN pooling
is not allowed.
c. When specifying the use of a split tunnel configuration, use split-tunnel forward mode.
d. Create and apply the applicable SSID profile.
When creating a new virtual AP profile In the WebUI, you can also configure the SSID at the same time. For
information about AP profiles, see Understanding AP Configuration Profiles on page 569.
5. (Optional) Create a list of network names resolved by corporate DNS servers.
Configuring the Session ACL Allowing Tunneling
First you need to configure a session ACL that “permits” corporate traffic to be forwarded (tunneled) to the
controller, and that routes, or locally bridges, local traffic.
In the WebUI
1. Navigate to the Configuration > Security > Access Control > Policies page.
2. Click Add to create a new policy.
3. Enter the policy name in the Policy Name field.
4. From the Policy Type drop-down list, select Session.
5. From the IP Version drop-down list, select IPv4 or IPv6.
6. To create the first rule:
a. Under Rules, click Add.
b. Under Source, select any.
c. Under Destination, select any.
d. Under Service, select service. In the service drop-down list, select svc-dhcp.
e. Under Action, select permitforIPv4 orcaptivefor IPv6.
f. Click Add.
7. To create the next rule:
a. Under Rules, click Add.
b. Under Source, select any.
c. Under Destination, select alias.
The following steps define an alias representing the corporate network. Once defined, you can use the alias
for other rules and policies. You can also create multiple destinations the same way.
8. Under the alias section, click New. Enter a name in the Destination Name field.
a. Click Add.
b. For Rule Type, select Network.
c. Enter the public IP address of the controller.
d. Enter the Network Mask/Range.
e. Click Add to add the network range.
f. Click Apply. The new alias appears in the Destination menu.
9. Under Destination, select the alias you just created.
10.Under Service, select any.
11.Under Action, select permitfor IPv4 or captivefor IPv6.
Dell Networking W-Series ArubaOS 6.4.x | User Guide Remote Access Points | 750