Administrator Guide

Table Of Contents
7. Define IKE Policies:
(host)(config) #crypto isakmp policy <priority>
encryption {3des|aes128|aes192|aes256|des}
version v1|v2
authentication {pre-share|rsa-sig|ecdsa-256ecdsa-384}
group {1|2|19|20}
hash {md5|sha|sha1-96|sha2-256-128|sha2-384-192}
lifetime <seconds>
Configuring a VPN for L2TP/IPsec with IKEv2 in the WebUI
Only clients running Windows 7 (and later versions), StrongSwan 4.3, and Dell VIA support IKEv2. For additional
information on the authentication types supported by these clients, see Working with IKEv2 Clients on page
413."
Use the following procedures to in the WebUI to configure a remote access VPN for IKEv2 clients using
certificates.
l Defining Authentication Method and Server Addresses on page 421
l Defining Address Pools on page 421
l Enabling Source NAT on page 421
l Selecting Certificates on page 422
l Configuring IKE Policies on page 422
l Setting the IPsec Dynamic Map on page 423
l Finalizing WebUI changes on page 424
Defining Authentication Method and Server Addresses
1. Define the authentication method and server addresses.
2. Navigate to Configuration > Advanced Services > VPN Services and click the IPSEC tab.
3. To enable L2TP, select Enable L2TP (this is enabled by default).
4. Select the authentication method for IKEv1 clients. The currently supported methods include:
n Password Authentication Protocol (PAP)
n Extensible Authentication Protocol (EAP)
n Challenge Handshake Authentication Protocol (CHAP)
n Microsoft Challenge Handshake Authentication Protocol (MSCHAP)
n Microsoft Challenge Handshake Authentication Protocol version 2 (MSCHAPv2)
5. Configure the IP addresses of the primary and secondary Domain Name System (DNS) servers and primary
and secondary Windows Internet Naming Service (WINS) Servers that are pushed to the VPN client.
Defining Address Pools
Next, define the pool from which the clients are assigned addresses.
1. In the Address Pools section of the IPSEC tab, click Add to open the Add Address Pool page.
2. Specify the pool name, the start address, and the end address.
3. Click Done.
Enabling Source NAT
In the Source NAT section of the IPSEC tab, select Enable Source NAT if the IP addresses of clients must be
translated to access the network. If you enabled source NAT, click the NAT pool drop-down list and select an
existing NAT pool. If you have not yet created the NAT pool you want to use:
Dell Networking W-Series ArubaOS 6.4.x | User Guide Virtual Private Networks | 421