ClientOperating System SupportedSuite-B

IKE Authentication

SupportedSuite-B IPsec

Encryption

lWindows 7
lWindows Vista
lWindows XP
lIKEv1Cli entsusing ECDSACertificates
lIKEv1/IKEv2Clients using ECDSA
Certificateswi thL2TP/PPP /EAP-TLS
certificateuser-authentication
lAES-128-GCM
lAES-256-GCM

Table74 :

ClientSupport for Suite-B

The Suite-B algorithmsdescribed in Table 73 are also supported by Site-to-Site VP Ns between Dell controllers,or
between a controller and a server runningWindows 2 008 or StrongSwan 4.3.
Working w ith IKEv2 Clients
Not all clients support thebo th the IKEv1 and IKEv2 protocols. Only the clients in Table 75 support IKEv2 with
the followingauthenticati on types:

Windows 7 Client StrongSwan4.3 Client VIA Client

lMachine authenticationw ith
Certificates
lUser-namepassword
authenticationusing EAP-
MSCHAPv2or PEAP-
MSCHAPv2
lUsersmart-card
authenticationwi thEAP-TLS /
IKEv2
NOTE:Wi ndows 7 clients using
IKEv2do not support pre-shared
keyauthentication.
lMachine authenticationw ith
Certificates
lUser-namepassword
authenticationusing EAP-
MSCHAPv2.
lSuite-Bcryptographic
algorithms
lMachine authenticationw ith Certificates
lUser-namepassword authentication using
EAP-MSCHAPv2
lEAP-TLSusing Microsoftcert repository
NOTE:VIA cli entsusing IKEv2do not support
pre-sharedkey authentication.

Table75 :

VPN Clients SupportingIKEv2

Understand ing Supported VP N AAA Deploymen ts
If you want to simultaneously deploy various combinations of a V PN client, RAP-psk, RAP-certs and CAP o n the
same controller,see Table 76.
Each row in this table specifies t he allowedcombinati ons of AAA servers for simultaneous deployment.
Configuration rulesinclude:
lRAP-certs can only use LocalDB-AP
lA RAP-psk and RAP-cert can only terminate on the same controllerif t heRA P VPN profile’s AAA server uses
Local-db.
lIf a RAP-psk is using an externalA AA server,t henthe RAP -certc annotbe t erminatedon the same controller.
lClients can use any type of AAA server, regardless of RAP/CAP authentication configuration server.

VPN Client RAP psk RAP certs CAP

ExternalAAA server 1 LocalDB LocalDB-AP CPSEC-whitelist

Table76 :

SupportedVPN AAA Deployments

DellPowerConnect W- Series ArubaOS 6.2 | UserGuide VirtualPrivate Networks | 273