Users Guide

Table Of Contents
390 | Virtual Private Networks Dell PowerConnect W-Series ArubaOS 6.1 | User Guide
You then specify the default user role and authentication server group in the VPN authentication default profile,
as described in the following sections.
Selecting an IKE protocol
Controllers running ArubaOS version 6.1 and later support both IKEv1 and the newer IKEv2 protocol to establish
IPsec tunnels. IKEv2 is simpler, faster, and a more reliable protocol than IKEv1, though both IKEv1 and IKEv2
support the same suite-B cryptographic algorithms.
If your IKE policy uses IKEv2, you should be aware of the following caveats when you configure your VPN:
ArubaOS does not support separate pre-shared keys for both directions of an exchange; the same pre-shared
key must be used by both peers. ArubaOS does not support mixed authentication with both pre-shared keys
and certificates; each authentication exchange requires a single authentication type. (For example, if a client
authenticates with a pre-shared key, the controller must also authenticate with a pre-shared key.)
ArubaOS does not support IKEv2 mobility (MOBIKE), Authentication Headers (AH) or IP Payload
Compression Protocol (IPComp).
Suite-B Encryption Licensing
Dell controllers support Suite-B cryptographic algorithms when the Advanced Cryptography (ACR) license is
installed. Table 67 describes the Suite-B algorithms supported by ArubaOS IKE Policies and IPsec tunnels. For
further details on configuring a VPN to use Suite-B algorithms, see “Configuring a VPN for L2TP/IPsec with
IKEv2” on page397.
The following VPN clients support Suite-B algorithms when establishing an L2TP/IPsec VPN.
The Suite-B algorithms described in Table 67 are also supported by Site-to-Site VPNs between Dell controllers, or
between an Dell controller and a server running Windows 2008 or StrongSwan 4.3.
Table 67 Suite-B Algorithms Supported by the ACR License
IKE Policies Suite-B for IPsec tunnels
hash: SHA-256-128, SHA-384-192 Encryption: AES-128-GCM, AES-256-GCM
Diffie-Hellman (DH) Groups : ECP-256, ECP-384 Perfect Forward Secrecy (PFS): ECP-256, ECP-384
Pseudo-Random Function (PRF) : HMAC_SHA_256, HMAC_SHA_384
Suite-B certificates: ECDSA-256, ECDSA-384
NOTE: IKE Suite-B AES-128-GCM and AES-256-GCM encryption is supported by the ArubaOS hardware. IKE Suite-B Diffie-Hellman
and Certificate-based signature operations and hash, PFS, and PRF algorithm functions are performed by the ArubaOS software.
Table 68 Client Support for Suite-B
Client Operating System
Supported Suite-B
IKE Authentication
Supported Suite-B IPsec
Encryption
Windows 7
Windows Vista
Windows XP
IKEv1 Clients using ECDSA Certificates
IKEv1/IKEv2 Clients using ECDSA Certificates
with L2TP/PPP/EAP-TLS certificate user-
authentication
AES-128-GCM
AES-256-GCM