a. UnderCA Certificate Assigned for VPN-clients, click Add.
b. Selecta CA certificat e fromthe drop-down list of CA certificat es imported in the controller.
c. Click Done.
d. Repeatt he above steps to add additional CA certificates.
Defining IKEv1 Shared Keys
If you are configuringa VPN t o support IKEv1 and clients using pre-sharedkeys, You can configure a globalIKE key
or configurean IKE key for each subnet. Makes urethat this key matches the key on the client.
1. I n the IKE SharedSecret s section of the IPsec tab, click Add to open the Add IKE Secret page.
2. E ntert hesubnet and subnet mask. To make the IKE key global, specify 0.0.0.0 for both values.
3. E nterthe IKE Shared Secret andVerify IKE Shared Secret.
4. Click D one to apply the configurations.
Configuring IKE Polici es
ArubaOScontains severalpredefined default IKE policies, as described in Table 79. If you do not want to use any of
these predefinedpolicies, you can use the procedures below to edit an existing policy or create your own custom IKE
policy instead.
NOTE:The IKE poli cy selections, along with any preshared key,need to be reflected in the VPN cl ient configuration. When using a
third-partyVPN cl ient, setthe VPN configuration on cl ients tom atchthe choices made above. In case the Dell dialer i sused, these
configurationneed to be made on the dial er prior to downloading the dialer onto the local client
1. Scroll down to the IKE Policies section of the IPSEC tab, then click Edit to edit an existing policy o r click Add
to create a new policy.
2. E nter a numberinto the Priority field to set the priorit y for this policy. Enter a priority t o 1 for the
configuration to take priority over the Default setti ng.
3. Select the IKE version. Click the Version drop-downlist and select V1 for IKEv1 or V2 for IKEv2.
4. Set t heE ncryption type. Clickt heEn cryption drop-downlist and select one o f the followingencryption t ypes.
lDES
l3DES
lAES128
lAES192
lAES256
5. Set t heHASH function. Click the Hash drop-down list and select one of the following hash types.
lMD5
lSHA
lSHA1-96
lSHA2-256-128
lSHA2-384-192
6. A rubaOSVPNs support client authentication using pre-sharedkeys, R SA digital certificates, or Elliptic Curve
Digital Signature Algorithm(E CDSA) certificates. To set the authentication type for the IKE rule, click the
Authentication drop-down list and select one of the following types:
lPre-Share(for IKEv1 clients using pre-sharedkeys)
lRSA (for clients using certificates)
lECDSA-256 (for clients using certificates)
DellPowerConnect W- Series ArubaOS 6.2 | UserGuide VirtualPrivate Networks | 277