Users Guide

Table Of Contents
244| BranchController Config for Controllers Dell Networking W-Series ArubaOS 6.5.x| User Guide
Parameter Description
Description
Certificate
For certificate authentication, select Certificate, then click the Server Cer-
tificate and CA certificate drop-down lists to select certificates previously
imported into the controller.
See
Management Access on page 824 for more information on managing
certificates.
DPD Parameters
Enable DPD
The DPD Parameters checkbox on the VPNtab enables or disables Dead
Peer Detection. When enabled, DPD uses IPsec traffic patterns to minimize
the number of IKE messages required to determine the liveliness of an IKE
peer. After a dead peer is detected, the branch controller tears down the
IPsec session. Once the network path or other failure condition has been cor-
rected, a new IPsec session is automatically re-established.
Policy Name
Policy
Number
IKE
Version
Encryption
Algorithm
Hash
Algorithm
Authentica
-tion
Method
PRF
Method
Diffie-
Hellman
Group
Default
protection
suite
10001 IKEv1 3DES-168 SHA 160 Pre-Shared
Key
N/A 2 (1024
bit)
Default RAP
Certificate
protection
suite
10002 IKEv1 AES -256 SHA 160 RSA
Signature
N/A 2 (1024
bit)
Default RAP
PSK
protection
suite
10003 AES -256 SHA 160 Pre-Shared
Key
N/A 2 (1024
bit)
Default RAP
IKEv2 RSA
protection
suite
1004 IKEv2 AES -256 SSHA160 RSA
Signature
hmac-
sha1
2 (1024
bit)
Default
Cluster PSK
protection
suite
10005 IKEv1 AES -256 SHA160 Pre-Shared
Key
Pre-
Shared
Key
2 (1024
bit)
Default IKEv2
RSA
protection
suite
1006 IKEv2 AES - 128 SHA 96 RSA
Signature
hmac-
sha1
2 (1024
bit)
Table 62: Default IKE Policy Setting