Users Guide

Table Of Contents
349| Virtual Private Networks Dell Networking W-Series ArubaOS 6.5.x| User Guide
Configuring a Basic L2TP VPN in the WebUI
Use the following procedures in the WebUI to configure a remote access VPN for L2TP IPsec for clients using
pre-shared keys, certificates, or EAP for authentication:
l Defining Authentication Method and Server Addresses on page 353
l Defining Address Pools on page 353
l Enabling Source NAT on page 354
l Selecting Certificates on page 354
l Defining IKEv1 Shared Keys on page 350
l Configuring IKE Policies on page 354
l Setting the IPsec Dynamic Map on page 355
l Finalizing WebUI changes on page 356
Defining Authentication Method and Server Addresses
1. Define the authentication method and server addresses.
2. Navigate to Configuration > Advanced Services > VPN Services and click the IPSECtab.
3. To enable L2TP, select Enable L2TP (this is enabled by default).
4. Select the authentication method for IKEv1 clients. Currently supported methods include:
n Password Authentication Protocol (PAP)
n Extensible Authentication Protocol (EAP)
n Challenge Handshake Authentication Protocol (CHAP)
n Microsoft Challenge Handshake Authentication Protocol (MSCHAP)
n Microsoft Challenge Handshake Authentication Protocol version 2 (MSCHAPv2)
5. Configure the IP addresses of the primary and secondary Domain Name System (DNS) servers and the
primary and secondary Windows Internet Naming Service (WINS) Server that are pushed to the VPN client.
Defining Address Pools
Next, define the pool from which the clients are assigned addresses:
1. In the Address Pools section of the IPSEC tab, click Add to open the Add Address Pool page.
2. Specify the pool name, start address, and end address.
3. Click Done.
RADIUS Framed-IP-Address for VPN Clients
IP addresses are usually assigned to VPN clients from configured local address pools. However, the Framed-IP-
Address attribute that is returned from a RADIUS server can be used to assign the IPaddress.
VPN clients use different mechanisms to establish VPN connections with the controller, such as IKEv1, IKEv2,
EAP, or a user certificate. Regardless of how the RADIUS server is contacted for authentication, the Framed-IP-
Address attribute is assigned the IP address as long as the RADIUS server returns the attribute. The Framed-IP-
Address value always has a higher priority than the local address pool.
Enabling Source NAT
In the Source NAT section of the IPSEC tab, select Enable Source NAT if the IP addresses of clients must be
translated to access the network. If source NAT is enabled, click the NAT pool drop-down list and select an
existing NAT pool. To create a new NATpool:
1. Navigate to Configuration > Network > IP > NAT Pools.
2. Click Add.