Administrator Guide

Table Of Contents
l If you selected the User Role type, click the Target drop-down list and select a user role. The rule will be
applied to traffic from clients with the selected user role.
5. Click Done.
6. Click Apply.
VPN Configuration
Configure IPsec crypto maps and DTP settings for the branch controllers in a branch config group by navigating
to Configuration>Branch>Smart Config and selecting the VPN tab. The settings on the VPN tab are
described in the table below.
Parameter Description Description
IPSec maps
Name Name of the IPsec map.
Disable IPsec map Click this checkbox to temporarily disable a configured IPsec map without
deleting it from the branch config group.
Priority Priority level for the IPsec map, from 1-9998. An IPsec map with a smaller pri-
ority number will take precedence over a map with a greater priority num-
ber.
Source Network IP address the source network (the local network connected to the branch
controller).
Source Subnet Mask Subnet mask for the source network (the local network connected to the
branch controller).
Destination Network IP address the destination network (the remote network to which the local
branch network communicates).
Destination Subnet Mask Subnet mask for the source network (the remote network to which the local
branch network communicates).
Peer Gateway
Define the peer gateway.
l If you are configuring an IPsec map for a dynamically addressed
remote peer, give the peer gateway a default value of 0.0.0.0.
l If you are configuring an IPsec map for a dynamically addressed
remote peer, enter the IP address of the interface used by the remote
peer to connect to the L3 network .
Peer Certificate Subject
Name
If you use IKEv2 to establish a site-to-site VPN for a statically addressed
remote peer, identify the peer device by entering its certificate subject
name in the Peer Certificate Subject Name field.
NOTE: This field is not enabled until you select he Certificate option for the
Dynamically Addressed Peer setting. To identify a peer certificate's
subject name, issue the show crypto-local pki servercert <certname>
subject command in the master controller command-line interface.
Table 64: Branch Config Group VPN Settings
Dell Networking W-Series ArubaOS 6.4.x | User Guide BranchController Config for Controllers | 314