(host)(config) #crypto-local isakmp dpd idle-timeout <idle_seconds> retry-timeout <retry_
seconds> retry-attempts <number>

Understand ing Default IKE policies

ArubaOSincludes the following defaultIKE polici es.These policies are predefined andcannot be edited.

Policy Name Policy

Number

IKE

Version

Encryption

Algorithm

Hash

Algorithm

Authentica-

tion

Method

PRF

Method

Diffie-

Hellman

Group

Defaultprotection
suite
10001 IKEv1 3DES-168 SHA160 Pre-Shared
Key
N/A 2 (1024bit)
DefaultRAP
Certificateprotection
suite
10002 IKEv1 AES-256 SHA 160 RSA
Signature
N/A 2 (1024bit)
DefaultRAP PS K
protectionsuite
10003 AES-256 SHA 160 Pre-Shared
Key
N/A 2 (1024bit)
DefaultRAP IKEv2
RSAprotection suite
1004 IKEv2 AES -256 SSHA160 RSA
Signature
hmac-
sha1
2(1024 bit)
DefaultCluster PSK
protectionsuite
10005 IKEv1 AES-256 SHA160 Pre-Shared
Key
Pre-
Shared
Key
2(1024 bit)
DefaultIKEv2 RSA
protectionsuite
1006 IKEv2 AES - 128 SHA96 RSA
Signature
hmac-
sha1
2(1024 bit)
DefaultIKEv2 PSK
protectionsuite
10007 IKEv2 AES- 128 SHA96 Pre-shared
key
hmac-
sha1
2(1024 bit)
DefaultSuite-B
128bitECDSA
protectionsuite
10008 IKEv2 AES- 128 SHA256-128 ECDSA-256
Signature
hmac-
sha2-256
Random
ECP Group
(256bit)
DefaultSuite-B 256
bitECDSA protection
suite
10009 IKEv2 AES-256 SHA 384-192 ECDSA-384
Signature
hmac-
sha2-384
Random
ECP Group
(384bit)
DefaultSuite-B
128bitIKEv1 ECDSA
protectionsuite
10010 IKEv1 AES-GCM-
128
SHA256-128 ECDSA-256
Signature
hmac-
sha2-256
Random
ECP Group
(256bit)
DefaultSuite-B
256-bitIKEv1 ECDSA
protectionsuite
10011 IKEv1 AES-GCM-
256
SHA256-128 ECDSA-256
Signature
hmac-
sha2-256
Random
ECP Group
(256bit)

Table79 :

DefaultIKE P olicy Settings
Working with VPN Dial er
For Windows clients,a dialercan be downloaded from the controllerto auto-configure tunnel settings on the client.
DellPowerConnect W- Series ArubaOS 6.2 | UserGuide VirtualPrivate Networks | 293