
e. In the Settings tab, select the policy condition, and Edit Profile....
f. In the Advanced tab, select Vendor Specific, and click Add to add new vendor specific attributes.
g. Add new vendor specific attributes and click OK.
h. In the IP tab, provide the IP address of the OAW-IAP and click OK.
VPN Local Pool Configuration
The VPN local pool is used to assign an IP Address to the OAW-IAP after successful XAUTH VPN.
(host) # ip local pool "rapngpool" <startip> <endip>
Role Assignment for the Authenticated OAW-IAPs
Define a role that includes a src-nat rule to allow connections to the RADIUS server and for the Dynamic Radius
Proxy in the IAP to work. This role is assigned to IAPs after successful authentication.
(host) (config) #ip access-list session iaprole
(host) (config-sess-iaprole)#any host <radius-server-ip> any src-nat
(host) (config-sess-iaprole)#any any any permit
(host) (config-sess-iaprole)#!
(host) (config) #user-role iaprole
(host) (config-role) #session-acl iaprole
(host) (config-role) #!
VPN Profile Configuration
The VPN profile configuration defines the server used to authenticate the IAP (internal or an external server) and the
role assigned to the IAP after successful authentication.
(host) (config) #aaa authentication vpn default-iap
(host) (VPN Authentication Profile "default-iap") #server-group default
(host) (VPN Authentication Profile "default-iap") #default-role iaprole
For information about the VPN profile configuration on the OAW-IAP, see VPN Configuration on page 221.
Viewing Branch Status
To view the details of the branches connected to the switch, execute the show iap table command.
Example
This example shows the details of the branches connected to the switch:
(host) (config) #show iap table
IAP Table
---------
Branch Key
Statu-
s
Branch
Name
Inner IP VC MAC Address Bid(Subnet Name) Branch subnet
----------
-----
-
------ -------- ----------- ---------------------- ------------
bc91f01b57a7ba010302932-
d
6e5cf08b139ecac601a2024
UP
Instant
C0:42:2C
192.0.2.3
d8:c7:c8:c0:01:6-
c
0(22.22.22.0-22.22.22.20,
16)
3(83.83.83.084.84.84.255
400)
22.22.22.0/28
The output of this command includes the following parameters:
AOS-W Instant 6.2.1.0-3.3| User Guide IAP-VPN Configuration | 227
Kommentare zu diesen Handbüchern