274| Virtual Private Net works DellPowerConnect W- Series ArubaOS 6.2 | User Guide

VPN Client RAP psk RAP certs CAP

ExternalAAA server 1 ExternalAAA server 1 Notsupported CPSEC-whitelist
ExternalAAA server 1 ExternalAAA server 2 Notsupported CPSEC-whitelist
LocalDB LocalDB LocalDB-AP CPSEC-whitelist
LocalDB ExternalAAA server 1 Notsupported CPSEC-whitelist

Working with Ce rtificate Groups

The certificate group featureallows yo u to access multiple types of certificates on the same co ntroller.To create a
certificate group,use the following command:
(host) (config) #crypto-local isakmp certificate-group server-certificate server_certificate
ca-certificate ca_certificate
You can view existing certificate groups using:
show crypto-local isakmp certificate-group
Working with VPN Auth entication Profiles
VPN Authentication profiles identify a user rolefor authenticated VPN clients, an authentication server, and the
servergroup to which the authentication server belongs. Thereare three predefined VPN authenticatio n profiles:
default,default-rapand default-cap. These differentprofiles allow you to use different authentication servers,user
rolesand IP pools for VPN, remote AP and campus AP clients.
NOTE:The default and def ault-rap profil esare configurabl e, but thed efault-c ap profile cannot be edited.

Parameter default default-rap default-cap

DefaultRole for authenticatedusers default-vpn-role default-vpn-role sys-ap-role
0
Maximum allowed authentication failures
(Thenumber ofcontiguous authentication
failuresbefore the station is bl acklisted.)
0(feature is disabled) 0(feature is disabled) 0(featureis disabled)
Checkcertificate comm on name against
AAAserver
disabled enabled enabled
Authenticationserver group internal

Table77 :

PredefinedAuthenticationProfile settings
To edit the default VPN authentication profile:
1. N avigate to the Configuration > Security > Authentication > L3 Authentication page.
2. I n the Profiles list in the left window pane, select the default VPN Authentication Profile.
3. Click t he Default Roledrop-downlist and select the defaultuser role for authenticated VP N users. (For detailed
information on creating andmanaging user roles and policies, see "Roles and Policies" on page 296.)