529| Remote AccessPoints DellPowerConnect W- Series ArubaOS 6.2 | UserGuide
2. Click Add to crete a new policy.
3. Enter the policy name in the Policy Namefield.
4. From the Policy Type drop-downlist, select IPv4 Session.
5. To create the first rule:
a. Under Rules,click A dd.
b. UnderSource, select any.
c. Under Destination, select any.
d. UnderService, select service. In t he service drop-downlist, select svc-dhcp.
e. Under Action, select permit.
f. Click Add.
6. To create the next rule:
a. Under Rules,click A dd.
b. UnderSource, select any.
c. Under Destination, select any.
d. UnderService, select any.
e. Under Action, select route, and select the src-nat checkbox.
f. Click Add.
7. Click Apply.
.
NOTE:If you use a local DHCP server to obtain IP addresses, you mustdefine one addi tional ACL toperm it trafficbetween cli ents
withoutsource NATing the traffic. Add user alias internal-network any permitbefore any any any route
src-nat.
8. Click the User Roles tab.
a. Click Add.
b. Enter the Role Name.
c. Click Add underFi rewallPolici es.
d. In the Choose fromCo nfiguredPolicies menu, select the policy you just created.
e. Click Done.
Configuring the AAA Profi le in the WebUI
1. Navigate to the Security >Authentication >AAA Profiles page. From the AAA Profiles Summary list, click
Add.
2. Enter the AAA profile name, then click Add.
3. Select the AAA profile that you just created:
a. For Initial role, select the user role you just created.
b. For8 02.1X Authentication Default Role, select the appropriate role for your remote AP configuration, then
click Apply.
c. Under the AAA profile that you created, locate 80 2.1x Authentication Server Group,and select t he
authentication server groupt o use for your remote AP configuration, then click Apply.
NOTE:If you need to create an 802.1xauthentication server group, select new from the 802.1X Authentication Server Groupdrop-
down list, and enter theappropri ateparam eters.