Release Notes

Parameter Description
udpencap-behind-natdevice
Configure NAT-T if controller is behind NAT device. (For Windows VPN
Dialer only)
enable
Enable Nat-T. This is the recommended setting if the controller is behind a
NAT device.
disable
Disable Nat-T.
packet-dump
Issue this command in enable mode to troubleshoot an IPsec tunnel
establishment by looking at the packet exchanges between the controller
and the remote AP or the other IPsec peer. The packet dump output is
saved to a file named ike.pcap.
NOTE: This is a testing feature only, and should not be enabled on a
production network. To disable this feature, use the command no crypto
isakmp packet-dump.
Usage Guidelines
Use this command to configure the IKE pre-shared key, set the EAP authentication method for IKEv2 clients
using EAP user authentication, and enable source NAT if the IP addresses of clients need to be translated to
access the network.
Example
The following command configures an ISAKMP peer IP address and subnet mask. After configuring an ISAKMP
address and netmask, you will be prompted to enter the IKE preshared key.
(host)(config) #crypto isakmp address 10.3.14.21 netmask 255.255.255.0
Key:*******Re-Type Key:*******
Command History
Release Modification
ArubaOS 3.0 Command introduced.
ArubaOS 6.1 The eap-passthrough parameter was introduced.
Command Information
Platforms Licensing Command Mode
All platforms Base operating system Config mode on master controllers
Dell Networking W-Series ArubaOS 6.4.x | Reference Guide crypto isakmp | 276