Users Guide

Table Of Contents
351| Virtual Private Networks Dell Networking W-Series ArubaOS 6.5.x| User Guide
4. Set the Encryption type. Click the Encryption drop-down list and select one of the following encryption
types:
l DES
l 3DES
l AES128
l AES192
l AES256
5. Set the HASH function. Click the Hash drop-down list and select one of the following hash types:
l MD5
l SHA
l SHA1-96
l SHA2-256-128
l SHA2-384-192
6. ArubaOS VPNs support client authentication using pre-shared keys, RSA digital certificates, or Elliptic Curve
Digital Signature Algorithm (ECDSA) certificates. To set the authentication type for the IKE rule, click the
Authentication drop-down list and select one of the following:
l Pre-Share (for IKEv1 clients using pre-shared keys)
l RSA (for clients using certificates)
l ECDSA-256 (for clients using certificates)
l ECDSA-384 (for clients using certificates)
7. Diffie-Hellman is a key agreement algorithm that allows two parties to agree upon a shared secret, and is
used within IKE to securely establish session keys. To set the Diffie–Hellman Group for the ISAKMP policy,
click the Diffie–Hellman Group drop-down list and select one of the following groups:
l Group 1: 768-bit DiffieHellman prime modulus group.
l Group 2: 1024-bit DiffieHellman prime modulus group.
l Group 14: 2048-bit DiffieHellman prime modulus group.
l Group 19: 256-bit random DiffieHellman ECP modulus group.
l Group 20: 384-bit random DiffieHellman ECP modulus group.
Configuring Diffie–Hellman Group 1 and Group 2 types are not permitted if the controller is operating in FIPS mode.
8. Set the Security Association Lifetime to define the lifetime of the security association in seconds. The
default value is 7200 seconds. To change this value, uncheck the default checkbox and enter a value
between 300 and 86400 seconds.
9. Click Done.
Setting the IPsec Dynamic Map
Dynamic maps enable IPsec SA negotiations from dynamically addressed IPsec peers. ArubaOS has a
predefined IPsec dynamic map for IKEv1. If you do not want to use this predefined map, you can use the
procedures below to edit an existing map or create your own custom IPsec dynamic map instead:
1. Scroll down to the IPsec Dynamic Map section of the IPSEC tab, then click Edit by a map name to edit the
existing map or click Add to create a new map.
2. In the Name field, enter a name for the dynamic map.