Users Guide

Table Of Contents
Parameter Description
Description
PFS If you enable Perfect Forward Secrecy (PFS) mode, new session keys are
not derived from previously used session keys. Therefore, if a key is
compromised, that compromised key does not affect any previous session
keys. PFS mode is disabled by default. To enable this feature, click the PFS
drop-down list and select one of the following Perfect Forward Secrecy
modes:
l group1 : 768-bit Diffie–Hellman prime modulus group.
l group2 : 1024-bit Diffie–Hellman prime modulus group.
l group 14 : 2048-bit Diffie–Hellman prime modulus group.
l group19 : 256-bit random Diffie–Hellman ECP modulus group.
l group20 : 384-bit random Diffie–Hellman ECP modulus group.
Pre-Connect Select Pre-Connect to establish the VPN connection, even if there is no
traffic being sent from the local network. If you do not select this, the VPN
connection is established only when traffic is sent from the local network to
the remote network.
Trusted Tunnel Select Trusted Tunnel if traffic between the networks is trusted. If you do
not select this, traffic between the networks is untrusted.
Enforce NATT Select the Enforce NATT checkbox to enforce IKE and IPSEC NAT Traversal
(NAT-T) on UDP port 4500. This option is disabled by default.
Transform Sets
A transform set defines a specific encryption and authentication type used
by the dynamic peer. Click the Transform Set drop-down list to select a pre-
defined transform set or a transform set that was manually defined using
the Configuration>Advanced Services > VPN Services > Advanced page
of the master controller WebUI, then click the arrow button by the drop-
down list to add that transform set to the IPsec map.
Dynamically Addressed
Peer
Select either the Pre-shared Key or Certificate options to define security
options for a dynamically address peer.
Pre-shared Key For pre-shared key authentication, select Pre-Shared Key, then enter a
shared secret in the IKE Shared Secret and Verify IKE Shared Secret
fields. This authentication type is generally required in IPsec maps for a
VPN with dynamically addressed peers, but can also be used for a static
site-to-site VPN.
Dell Networking W-Series ArubaOS 6.5.x | User Guide BranchController Config for Controllers | 243