Figure 173: SampleS plit TunnelEnvironment
Figure1 73 displays corporate traffici s GRE tunneledto the controller through a trustedtunnel and local traffic is
source NATed and bridgedo n the wired interface based on the configureduser role and session ACL.
Configuring Split Tunn eling
The procedureto configuresplit tunneling requiresthe following steps. E ach step is described in detail later in this
chapter.
NOTE:The spli ttunneli ng featurerequires the PEFNG license. If you do not have the PEFNG license on your controller, you must
install it beforeyou configure split tunneling. Fordetailson i nstalling licenses, see "Software Licenses" on page 100.
1. Define a session ACL thatforwards only corporate traffic to the controller.
a. Configure a netdestination for the corporate subnets.
b. Create rulest o permit DHCP and corporate traffic to the corporate controller.
c. Apply the session ACLto auser role. For information about user roles and policies, see Roles and Policies o n
page 296.
2. (Optional) Configurean A CL that restricts remote AP users from accessing the remoteA P local debugging
homepage.
3. Configure the remote AP’s AAA profile.
a. Specify the authentication method (802.1x or PSK) and the default user role forauthenticated users. The user
rolespeci fied in the AAA profile must contain the session ACL defined in the previous step.
b. (Optional) Use the remote AP’s AAA profile to enable RADIUS accounting.
4. Configure the virtual AP profile:
a. Specify which AP group or AP to which thevirtual AP profile applies.
b. set the VLAN used for split tunneling.Only one VLAN can be configuredfor split tunneling; VLAN pooling is
not allowed.
c. When specifying the use of a split tunnel configuration,use “split-tunnel” forward mode.
d. Create and apply the applicableSSID profile.
NOTE:When cr eating a new virtual AP profile In the WebUI, youcan al soconfigure the SS IDat the same time. For information
aboutAP profil es, see "Understanding AP Configuration Profiles" on page 396.
5. (Optional) Create a list of network names resolved by corporate DNS servers.
DellPowerConnect W- Series ArubaOS 6.2 | UserGuide RemoteAccessPoints | 536