728| Instant AP VPN Support DellPowerConnect W- Series ArubaOS 6.2 | UserGuide
lL2 Switching Mode:In this mode, Instant supports distributed L2 and centralizedL2 swit chingmodes of
connection to corporate. When an Instant AP registers with the controller and has a L2 mode DHCP poo l
configured,the controller automatically adds the GRE or VPN tunnel associated to this IA P into the VLAN
multicast table. This allowst heclients co nnectingto this L2 mode VLA N to be part of the same L2 domain on
controller.
lL3 Routing Mode:I nthis mode, Instant supports L3 routing mode of connection to corporate.The VC assigns
an IP addresses from the configuredsubnet and forwards traffic to both corporate and non-corporate destinations.
Instant AP takes care of routing on the subnet and alsoadds a route on the controller after the VPN tunnel is set
up duringthe registration of the subnet. When the Instant AP registers with a L3 mode DHCP pool, the
controllerautomatically adds a route t o this DHCP subnet enabling routing of traffic from the corporate to
clients on this VLAN in the branch.
VPN Configuration
The followingVP N configurationsteps on the controller, enableI APs to terminate their VPN connection on the
controller:

Whitelist DB Co nfiguration

Controller Whiteli st DB

You can uset hefollowing CLI command to configure the whitelist DB i ft heco ntrolleris acting as the whitelist
entry:
(host) #local-userdb-ap add mac-address 00:11:22:33:44:55 ap-group test
The ap-groupparameter is not used for any co nfiguration,but needs to be configured. The parameter can be any
valid string.I fan external whitelist is being used, the MAC address of the AP needs to be saved in the Radius server
as a lower case entry without any delimiter.

External Whitelist DB

The externalwhitelist functionality enables you to configure the RAD IUS server to use an external whitelist for
authentication of MAC addresses of RAPs.
If you are using Windows 2003 server, perform the following steps to configure external whitelist on it. There are
equivalentsteps available for Windows Server 2008 and other RAD IUS servers.
1. Add the MAC addresses forall the RAPs in the Active D irectory of the Radius server:
a. Open the Active Directory and Computers window, add a new user and specify the MAC address (without
the colon delimiter)o ft heR AP for the username and password.
b. Right-click the userthat you have just created and click Properties.
c. In the Dial-in tab, select Allow access in the Remote Access Permission secti on and click OK.
d. Repeat Step a throughStep b for all RAPs.
2. Define the remote access policy in the Internet Authentication Service:
a. In the Internet Authent ication Service window, select Remote Access Policies.
b. Launchthe wizard to configure a new remote access policy.
c. Define filters andselect select grant remot e access permission in the Permissions window.
d. Right-clickt he policy that you have just created and select Properties.
e. In the Settings tab, select the policy conditio n,and Edit Profile....
f. In the Advanc edt ab, select Vendor Specific,and click Add to add new vendor specific attributes.
g. Add new vendor specific attributes and click OK.