Reference Guide

Table Of Contents
6 | Introduction Dell PowerConnect W-Series ArubaOS 6.1 CLI | Reference Guide
crypto pki-import
{CRL|IntermediateCA|
OCSPResponderCert|
OCSPSignerCert} <name>
CRL, IntermediateCA, OCSPResponderCert and OCSPSignerCert certificates can
now be imported.
crypto-local ipsec-map
<map> <priority> peer-
cert-dn <peer-dn>
If you are using IKEv2 to establish a site-to-site VPN to a statically addressed
remote peer, identify the peer device by entering its certificate subject name in the
Peer Certificate Subject Name field
crypto-local ipsec-map
<map> <priority> peer-
fqdn any-fqdn|fqdn-id
<peer-id-fqdn>
For site-to-site VPNs with dynamically addressed peers, specify a fully qualified
domain name (FQDN) for the controller.
crypto-local ipsec-map
<map> <priority> set pfs
{group1|group2|group19|gr
oup20}
The set pfs command introduced the group19 and group20 parameters.
group19: 256-bit random Diffie Hellman ECP modulus group. (For IKEv2 only)
group20: 384-bit random Diffie Hellman ECP modulus group. (For IKEv2 only)
crypto-local isakmp key
fqdn <ike-id-fqdn>
Configure the PSK for the specified FQDN.
crypto-local isakmp key
fqdn-any
Configure the PSK for any FQDN.
crypto-local pki The following parameters were added for the certificate revocation feature:
CRL
Intermediate CA
OCSPResponderCert
OCSPSignerCert
global-ocsp-signer-cert
rcp
service-ocsp-responder
firewall amsdu| clear-
sessions-role-update
prohibit-ip-spoofing|
The parameter amsdu, when enabled, causes Aggregated Medium Access Control
Service Data Units (AMSDU) packets to be dropped.
The parameter clear-sessions-role-update clears the datapath sessions when
roles are updated.
The funtionality of the prohibit-ip-spoofing feature was enhanced. In previous
versions of ArubaOS, this feature checked only the source IP and the source MAC
address in the frame. Starting with ArubaOS 6.1, this feature also checks the
destination IP and the destination MAC address in the frame.
ids dos-profile Added the following new parameters to detect Meiners DoS Power Save attack:
detect-power-save-dos-attack
power-save-dos-min-frames
power-save-dos-quiet-time
power-save-dos-threshold
ids unauthorized-device-
profile
Added the following parameter to internally generate a list of valid SSIDs to use in
addition to the user configured list of Valid and Protected SSIDs
detect-valid-ssid-misuse
interface fastethernet |
gigabitethernet tunneled-
node-port
The parameter muxport has had a name change to tunneled-node-port. The
functionality has not changed.
interface loopback The parameter ipv6 address was added.
interface vlan option-82 Allows a DHCP relay agent to insert circuit specific information (about the AP and
SSID) into a request that is being forwarded to a DHCP server.
Command Parameter Description