Users Guide

Table Of Contents
343| Virtual Private Networks Dell Networking W-Series ArubaOS 6.5.x| User Guide
You then specify the default user role and authentication server group in the VPN authentication default
profile, as described in the sections below.
ESP Tunnel Mode is the only supported IPsec mode of operation. ArubaOS does not support AH and Transport
modes.
Selecting an IKE protocol
Controllers running ArubaOS version 6.1 and later support both IKEv1 and the newer IKEv2 protocol to
establish IPsec tunnels. Though both IKEv1 and IKEv2 support the same suite-B cryptographic algorithms,
IKEv2 is a simpler, faster, and more reliable protocol than IKEv1.
If your IKE policy uses IKEv2, you should be aware of the following caveats when you configure your VPN:
l ArubaOS does not support separate pre-shared keys for both directions of an exchange; both peers must
use the same pre-shared key. ArubaOS does not support mixed authentication with both pre-shared keys
and certificates; each authentication exchange requires a single authentication type. For example, if a client
authenticates with a pre-shared key, the controller must also authenticate with a pre-shared key.
l ArubaOS does not support IKEv2 Authentication Headers (AH) or IP Payload Compression Protocol
(IPComp).
l Starting from ArubaOS 6.5, ArubaOS supports the functionality where the non-Aruba devices can fragment
the large IKE_AUTH packets using the standards described in the RFC 7383 Internet Key Exchange
Protocol Version 2 (IKEv2) message fragmentation when the Aruba device acts as a responder and not as an
initiator.
Understanding Suite-B Encryption Licensing
Dell controllers support Suite-B cryptographic algorithms when the Advanced Cryptography (ACR) license is
installed. Table 73 describes the Suite-B algorithms supported by ArubaOS IKE Policies and IPsec tunnels. For
further details on configuring a VPN to use Suite-B algorithms, see Configuring a VPN for L2TP/IPsec with IKEv2
on page 353.
IKE Policies Suite-B for IPsec tunnels
hash: SHA-256-128, SHA-384-192 Encryption: AES-128-GCM, AES-256-GCM
Diffie-Hellman (DH) Groups: ECP-256, ECP-384 Perfect Forward Secrecy (PFS): ECP-256, ECP-
384
Pseudo-Random Function (PRF): HMAC_SHA_256,
HMAC_SHA_384
Suite-B certificates: ECDSA-256, ECDSA-384
Table 73: Suite-B Algorithms Supported by the ACR License
The ArubaOS hardware supports IKE Suite-B AES-128-GCM and AES-256-GCM encryption. ArubaOS software
performs the IKE Suite-B Diffie-Hellman and Certificate-based signature operations, and hash, PFS, and PRF
algorithm functions.
The following VPN clients support Suite-B algorithms when establishing an L2TP/IPsec VPN: