Concept Guide

Table Of Contents
aaa authentication vpn
aaa authentication vpn <profile-name>
cert-cn-lookup
clone <source>
default-role <guest>
export-route
max-authentication-failures <number>
no ...
pan-integration
radius-accounting
server-group <group>
user-idle-timeout
Description
This command configures VPN authentication settings.
Syntax
Parameter Description Default
<profile-name>
There are three VPN profiles: default,
default-rap or default-cap.
This allows users to use different AAA
servers for VPN, RAP and CAP clients.
NOTE: The default and default-rap
profiles are configurable. The default-cap
profile is not configurable and is
predefined with the default settings.
cert-cn-lookup
If you use client certificates for user
authentication, enable this option to verify
that the certificate's common name exists
in the server. This parameter is enabled by
default in the default-cap and default-rap
VPN profiles, and disabled by default on all
other VPN profiles.
clone <source>
Copies data from another VPN
authentication profile. Source is the profile
name from which the data is copied.
default-role <role>
Role assigned to the VPN user upon login.
NOTE: This parameter requires the Policy
Enforcement Firewall for VPN Users (PEFV)
license.
guest
export-route
Exports a VPN IP address as a route to the
external world. See the show ip ospf com-
mand to view the link-state advertisement
(LSA) types that are generated.
enabled
Dell Networking W-Series ArubaOS 6.5.x | Reference Guide aaa authentication vpn | 70