Working with VPNs
Securing wireless client sessions with VPNs
16-4
Configure an IPSec profile for wireless client VPN
1. On the page Controller > VPN > IPSec select Add Policy, and define a policy similar to
this:
Note the selections made in the sample Add/Edit security policy page above. See the
online help for option descriptions.
Option Value to set Notes
General Enabled
Name User-defined
Phase 1 mode Aggressive mode Aggressive mode requires that a group be
configured. See Local group list on page 16-11.
Mode Tunnel with Virtual IP Allows IP addresses to be assigned to the wireless
clients.
Interface LAN port
Encryption algorithm Select as desired
Perfect Forward Secrecy Leave enabled
Accept any peer Enabled Accepts any wireless client.
XAUTH > Authentication Enabled
Allocate address from VPN address pool First define address pool on Network > Address
allocation.
Security policy Subnet and Mask of
0.0.0.0
A Subnet and Mask of 0.0.0.0. causes all wireless
traffic between the client and the controller to be
accepted.