476| Secure Ente rprise Mesh DellPowerConnect W- Series ArubaOS 6.2 | User Guide
a. Makes ureVirtual AP enable i s selected.
b. From the VLAN drop-down menu, select the VLAN ID for the mesh private VLAN.
c. From the Forward mode drop-down menu,select split-tunn el.
d. Click Apply.
Provisioning a Rem ote Mesh Portal In the CLI
Reprovisioning the AP causes it to automatically reboot. When you use the CLI to reprovision a mesh node, you
may also provision other AP sett ings.
(host)(config) #provision-ap
read-bootinfo ap-name <name>
mesh-role remote-mesh-portal
reprovision ap-name <name>
Additiona l Information
By default,the data frames the mesh portal receives on its mesh link are forwardedaccording to the bridge table
entries on the portal. However,frames received on mesh private VLA N (MPV) are treated differentlyby the remote
mesh portal.These frames are treated the same as frames receivedo na split SSID and are routed ratherthan
bridged.Mesh points o btain DHCP addresses from the corporate network. then register with the controller using
these IP addresses. Whenthese mesh points send and receive PAPI co ntroltraffic from the main office controller, it
controls these mesh points just as if t hey were on a local VLAN. PAPI traffic containing keys and other secret
information receives IPsec encryption and decryption when it is forwarded to t hec ontrollerthrough the VPN tunnel.
Not all traffic from a mesh point is sent on the mesh private VLAN . Whena mesh point bridges data received via
its Ethernet interface or fromc lientsc onnectedto an access radio VAP, the mesh point does not tag the frame with
the mesh private VLAN tag when it sends the data through mesh link to the remote mesh portal. Note that t he
mesh point may still tag the framedepending on the VLAN of the virtual AP and the native VLAN s pecified in the
system profile.Care must be taken to assign the MPV valueso t hati t doesnot clash with any local tags assigned in
the meshnetwo rk.In this case, the portal performs the default operation that is to bridge the frame based on its
bridget able.
Traffic destinedt o the Internet is recognized as suchby the remote mesh portalbased on ACL rules.This t rafficis
NATed on the remote mesh portal’s Ethernet interface.