Users Guide

Table Of Contents
Dell PowerConnect W-Series ArubaOS 6.1 | User Guide Virtual Private Networks | 411
Default IKE policies
ArubaOS includes the following default IKE policies. These policies are predefined and cannot be edited.
VPN Dialer
For Windows clients, a dialer can be downloaded from the controller to auto-configure tunnel settings on the
client.
Configuring the VPN Dialer
Use the following procedures to configure the VPN dialer via the WebUI or command-line interfaces
In the WebUI
1. Navigate to the Configuration > Advanced Services > VPN Services > Dialers page. Click Add to add a new
dialer or click the Edit tab to edit an existing dialer.
2. Enter the Dialer Name that will be used to identify this setting.
3. Configure the dialer to work with PPTP or L2TP by selecting Enable PPTP or Enable L2TP.
Table 72 Default IKE Policy Settings
Policy Name
Policy
Number
IKE
Version
Encryption
Algorithm
Hash
Algorithm
Authentication
Method
PRF
Method
Diffie-
Hellman
Group
Default protection suite 10001 IKEv1 3DES-168 SHA 160 Pre-Shared Key N/A 2 (1024 bit)
Default RAP Certificate
protection suite
10002 IKEv1 AES -256 SHA 160 RSA Signature N/A 2 (1024 bit)
Default RAP PSK
protection suite
10003 IKEv1 AES -256 SHA 160 Pre-Shared Key N/A 2 (1024 bit)
Default RAP IKEv2 RSA
protection suite
1004 IKEv2 AES -256 SSHA160 RSA Signature hmac-sha1 2 (1024 bit)
Default Cluster PSK
protection suite
10005 IKEv1 AES -256 SHA160 Pre-Shared Key Pre-Shared
Key
2 (1024 bit)
Default IKEv2 RSA
protection suite
1006 IKEv2 AES - 128 SHA 96 RSA Signature hmac-sha1 2 (1024 bit)
Default IKEv2 PSK
protection suite
10007 IKEv2 AES - 128 SHA 96 Pre-shared key hmac-sha1 2 (1024 bit)
Default Suite-B 128bit
ECDSA protection suite
10008 IKEv2 AES - 128 SHA 256-128 ECDSA-256
Signature
hmac-sha2-
256
Random ECP
Group (256 bit)
Default Suite-B 256 bit
ECDSA protection suite
10009 IKEv2 AES -256 SHA 384-192 ECDSA-384
Signature
hmac-sha2-
384
Random ECP
Group (384 bit)
Default Suite-B 128bit
IKEv1 ECDSA
protection suite
10010 IKEv1 AES-GCM-128 SHA 256-128 ECDSA-256
Signature
hmac-sha2-
256
Random ECP
Group (256 bit)
Default Suite-B 256-bit
IKEv1 ECDSA
protection suite
10011 IKEv1 AES-GCM-256 SHA 256-128 ECDSA-256
Signature
hmac-sha2-
256
Random ECP
Group (256 bit)