Dell PowerConnect W-IAP92 Dell Instant 6.2.0.0-3.2.0.0 User Guide - Page 287

VPN Local Pool Configuration, VPN Profile Configuration, Radius Proxy for VPN Connected IAPs

Page 287 highlights

g. Add new vendor specific attributes and click OK. h. In the IP tab, provide the IP for the RAP and click OK. VPN Local Pool Configuration To configure the VPN Local Pool: 1. Navigate to the Configuration > Advanced Services > VPN Services > IPSec page. 2. Select (check) Enable L2TP. 3. Make sure that only PAP (Password Authentication Protocol) is selected for Authentication Protocols. 4. To configure the L2TP IP pool, click Add in the Address Pools section. Configure the L2TP pool from which the APs will be assigned addresses, then click Done. NOTE: The size of the pool should correspond to the maximum number of APs that the controller is licensed to manage. 5. To configure an Internet Security Association and Key Management Protocol (ISAKMP) encrypted subnet and preshared key, click Add in the IKE Shared Secrets section and configure the preshared key. Click Done to return to the IPSec page. 6. Click Apply. VPN Profile Configuration The VPN profile configuration defines the server used to authenticate the W-IAP (internal or an external server) and the role for W-IAP user. This role is used to define src-nat rule to Radius server to get Dynamic Radius proxy working. 1. Navigate to the Configuration > Security > Authentication > L3 Authentication page. 2. In the Profiles list, select the VPN Authentication Profile> default-iap. 3. For Default Role, enter the user role you created previously (for example, InstantAP). 4. Click Apply. 5. In the Profile list, under VPN Authentication Profile, select Server Group. 6. Select the server group from the drop-down menu. 7. Click Apply. For more information on VPN profile configuration, see "VPN Configuration" on page 261. Radius Proxy for VPN Connected IAPs The Radius proxy for VPN connected W-IAPs functionality defines the server used to authenticate the W-IAP (internal or an external server) and the role for W-IAP user. This role is used to define src-nat rule to Radius server to get Dynamic Radius proxy working. 1. Navigate to the Configuration > Security > Access Control > User Roles page. Click Add to create the sysadmin role. 2. For Role Name, enter sysadmin. 3. Under Firewall Policies, click Add. In Choose from Configured Policies, select the predefined allowall policy. Click Done. 4. Click Apply. For more information on VPN profile configuration, see "VPN Configuration" on page 261. Dell PowerConnect W-Series Instant Access Point 6.2.0.0-3.2.0.0 | User Guide 287 | IAP-VPN

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296

g.
Add new vendor specific attributes and click
OK
.
h.
In the
IP
tab, provide the IP for the RAP and click
OK
.
VPN Local Pool Configuration
To configure the VPN Local Pool:
1.
Navigate to the
Configuration > Advanced Services > VPN Services > IPSec
page.
2.
Select (check)
Enable L2TP
.
3.
Make sure that only
PAP
(Password Authentication Protocol) is selected for Authentication
Protocols.
4.
To configure the L2TP IP pool, click
Add
in the
Address Pools
section. Configure the L2TP
pool from which the APs will be assigned addresses, then click
Done
.
NOTE: The size of the pool should correspond to the maximum number of APs that the
controller is licensed to manage.
5.
To configure an Internet Security Association and Key Management Protocol (ISAKMP)
encrypted subnet and preshared key, click
Add
in the IKE Shared Secrets section and
configure the preshared key. Click
Done
to return to the IPSec page.
6.
Click
Apply
.
VPN Profile Configuration
The VPN profile configuration defines the server used to authenticate the W-IAP (internal or an
external server) and the role for W-IAP user. This role is used to define
src-nat
rule to Radius
server to get Dynamic Radius proxy working.
1.
Navigate to the
Configuration > Security > Authentication > L3 Authentication
page.
2.
In the Profiles list, select the
VPN Authentication Profile> default-iap
.
3.
For Default Role, enter the user role you created previously (for example, InstantAP).
4.
Click
Apply
.
5.
In the
Profile
list, under
VPN Authentication Profile
, select
Server Group
.
6.
Select the server group from the drop-down menu.
7.
Click
Apply
.
For more information on VPN profile configuration, see
"VPN Configuration" on page 261
.
Radius Proxy for VPN Connected IAPs
The Radius proxy for VPN connected W-IAPs functionality defines the server used to authenticate
the W-IAP (internal or an external server) and the role for W-IAP user. This role is used to define
src-nat
rule to Radius server to get Dynamic Radius proxy working.
1.
Navigate to the
Configuration > Security > Access Control > User Roles
page. Click
Add
to create the sysadmin role.
2.
For Role Name, enter
sysadmin
.
3.
Under Firewall Policies, click
Add
. In Choose from Configured Policies, select the predefined
allowall policy. Click
Done
.
4.
Click
Apply
.
For more information on VPN profile configuration, see
"VPN Configuration" on page 261
.
Dell PowerConnect W-Series Instant Access Point
6.2.0.0-3.2.0.0
|
User Guide
287
|
IAP-VPN