MSM7xx Controllers Configuration Guide v6.4.0

Configure an IPSec profile for wireless client VPN
On the page Controller >> VPN > IPSec select Add New Policy, and define a policy similar
to this:
Note the selections made in the sample Add/Edit security policy page above. See the online
help for option descriptions.
NotesValue to setOption
EnabledGeneral
User-definedName
Aggressive mode requires that a
group be configured.
Aggressive modePhase 1 mode
Allows IP addresses to be assigned
to the wireless clients.
Tunnel with Virtual IPMode
LAN portInterface
Select as desiredEncryption algorithm
Leave enabledPerfect Forward Secrecy
Accepts any wireless client.EnabledAccept any peer
EnabledXAUTH > Authentication
First define address pool on
Network > Address allocation.
VPN address poolAllocate address from
A Subnet and Mask of 0.0.0.0.
causes all wireless traffic between
the client and the controller to be
accepted.
Subnet and Mask of 0.0.0.0Security policy
Securing wireless client sessions with VPNs 509