272| Virtual Private Net works DellPowerConnect W- Series ArubaOS 6.2 | User Guide
NOTE:A server-derived role, ifpresent, takes precedence over the default user role.
You then specify the default userrole and authentication server group in the VPN authentication default profile,as
described in the following sections.
Selecting a n IKE protocol
Controllersrunning ArubaOS version 6.1 and latersupport both I KEv1 and the newer IKEv2 protocol to establish
IPsec tunnels. IKEv2 is simpler, faster, and a more reliableproto col than IKEv1, though both IKEv1 and IKE v2
support the sames uite-B cryptographicalgorithms.
If your IKE policy uses I KEv2, you should be aware of the following caveats when you configure your VPN:
lArubaOSdoes not support separate pre-shared keys for both directions of an exchange; the same pre-sharedkey
must be used by both peers. ArubaOSdoes not support mixed authentication with both pre-shared keys and
certificates; each authentication exchange requiresa si ngleauthentication t ype. (For example,if a client
authenticates with a pre-shared key,t he controllermust also authenticate wi th a pre-sharedkey.)
lArubaOSdoes not support IKEv2 mobility (MOBIKE), Authentication Headers (AH) or IP P ayload
Compression Protocol (IPComp).
Understand ing Suite-B Encryption Lice nsing
Dell controllerssupport Suite-B cryptographic algorithms when the Advanced Cryptography (ACR) license i s
installed.Table 73 describes the Suite-B algorithms supported by ArubaOS IKE Po licies and IPsec tunnels. For
furtherdetails on configuring a VPN to use Suite-B algorithms, see "Configuring a VPN for L2TP/IPsec with IKEv2
in the WebUI" on page 279.

IKE Policies Suite-Bfor IPs ectunnels

hash:S HA-256-128,SHA-384-192 Encryption:AES-128-GCM, AES-256-GCM
Diffie-Hellman (DH)Groups: ECP-256, ECP-384 PerfectForward Secrecy (PFS): ECP-256, ECP-384
Pseudo-Random Function(PRF): HMAC_SHA_256, HMAC_SHA_
384
Suite-Bcertificates: EC DSA-256,ECDSA-384

Table73 :

Suite-BAlgorithms Supportedby the ACR License

NOTE:IKE S uite-B AES-128-GCMand AES-256-GCMencryption is supported by the ArubaOS hardware. IKE Suite-B Diffie-Hellm an
andCertificate-based signature operations and hash, PFS, and PR Fal gorithm functionsare performed by the ArubaOS software.
The followingV PN clients support Suite-B algorithms when establishing an L2TP/IPsec VPN.