537| Remote AccessPoints DellPowerConnect W- Series ArubaOS 6.2 | UserGuide
Configuring the Session A CL Allowing Tu nneling
First you needto c onfigurea session ACL that “permits” corporate traffic to be forwarded(t unneled)to the
controller,and that “routes”, o r locallybridges, local traffic.
Using the WebUI
1. Navigate to the Configuration >Security >Access Con trol >Policies page.
2. Click Add to crete a new policy.
3. Enter the policy name in the Policy Name field.
4. From the Policy Type drop-down list, select Session.
5. From the IP Version drop-down list, select IPv4 or IPv6.
6. To create the first rule:
a. Under Rules, click Add.
b. Under Source,select an y.
c. Under Destination, select any .
d. Under Service,select service. In the service drop-down list, select svc-dhcp.
e. Under Action, select permitforIPv4 orcaptivefor IPv6 .
f. Click Add.
7. To create the next rule:
a. Under Rules, click Add.
b. Under Source,select an y.
c. Under Destination, select alias.
The followingsteps define an alias representing the corporate network. Oncedefined, you can use the alias for
other rulesand policies. You c an also create multipledesti nations the same way.
8. Under the alias section, click New. Enter a name in t heD estination Name field.
a. Click Add.
b. For Rule Type, select Network.
c. Enter the public IP address of the controller.
d. Enter the Network Mask/Range.
e. Click Add to add the network range.
f. Click Apply.The new alias appears in the Destinatio n menu.
9. Under Destination, select the alias you j ust created.
10. Under Service, select any.
11. Under Action, select permitfor IPv4 or captivefor IP v6.
12. Click Add.
13. To create t he next rule:
a. Under Rules, click Add.
b. Under Source,select user .
c. Under Destination, select any .
d. Under Service,select any.
e. Under Action, select any and check src-nat .
f. Click Add.
14. Click Apply.