Users Guide

Table Of Contents
Use the following procedures in the WebUI to configure a remote access VPN for L2TP IPsec for clients using
pre-shared keys, certificates, or EAP for authentication:
l Defining Authentication Method and Server Addresses on page 421
l Defining Address Pools on page 421
l Enabling Source NAT on page 421
l Selecting Certificates on page 422
l Defining IKEv1 Shared Keys on page 418
l Configuring IKE Policies on page 422
l Setting the IPsec Dynamic Map on page 423
l Finalizing WebUI changes on page 424
Defining Authentication Method and Server Addresses
1. Define the authentication method and server addresses.
2. Navigate to Configuration > Advanced Services > VPN Services and click on the IPSECtab.
3. To enable L2TP, select Enable L2TP (this is enabled by default).
4. Select the authentication method for IKEv1 clients. Currently supported methods include:
n Password Authentication Protocol (PAP)
n Extensible Authentication Protocol (EAP)
n Challenge Handshake Authentication Protocol (CHAP)
n Microsoft Challenge Handshake Authentication Protocol (MSCHAP)
5. Configure the IP addresses of the primary and secondary Domain Name System (DNS) servers and the
primary and secondary Windows Internet Naming Service (WINS) Server that are pushed to the VPN client.
Defining Address Pools
Next, define the pool from which the clients are assigned addresses:
1. In the Address Pools section of the IPSEC tab, click Add to open the Add Address Pool page.
2. Specify the pool name, start address, and end address.
3. Click Done.
RADIUS Framed-IP-Address for VPN Clients
IP addresses are usually assigned to VPN clients from configured local address pools. However, the Framed-IP-
Address attribute that is returned from a RADIUS server can be used to assign the address.
VPN clients use different mechanisms to establish VPN connections with the controller, such as IKEv1, IKEv2,
EAP, or a user certificate. Regardless of how the RADIUS server is contacted for authentication, the Framed-IP-
Address attribute is assigned the IP address as long as the RADIUS server returns the attribute. The Framed-IP-
Address value always has a higher priority than the local address pool.
Enabling Source NAT
In the Source NAT section of the IPSEC tab, select Enable Source NAT if the IP addresses of clients must be
translated to access the network. If you enabled source NAT, click the NAT pool drop-down list and select an
existing NAT pool. If you have not yet created the NAT pool you want to use:
1. Navigate to Configuration > IP > NAT Pools.
2. Click Add.
3. In the Pool Name field, enter a name for the new NAT pool, up to 63 alphanumeric characters.
Dell Networking W-Series ArubaOS 6.4.x | User Guide Virtual Private Networks |
417