Dell PowerConnect W-Airwave W-Airwave 7.2 Configuration Guide - Page 153

Advanced Services > VPN Services > L2TP, VPN Services > IKE

Page 153 highlights

IKE is a part of the IPSEC protocol suite, supporting security for VPNs with a shared session secret that produces security keys. NOTE: The IKE profile requires the controller to have a Remote Access Points license or a VPN Server license. Select Add to create a new IKE profile, or click the pencil icon next to an existing profile to edit. Table 78 describes the fields on the Advanced Services > VPN Services > IKE Add/Edit Detail page. Table 78 Advanced Services > VPN Services > IKE Add/Edit Detail Field Descriptions Field Default Description General Settings Folder Name Other Settings IKE Aggressive Group Name Top Blank Enable IKE RAP PSKL No Refresh/Caching IKE Shared Secrets Add IKE Policies Add Set the folder with which the IKE profile is associated. The drop-down menu displays all folders available for association with the IKE services profile. Enter the name of the IKE profile. Enter the authentication group name for aggressive mode. Make sure that the group name matches the group name configured in the VPN client software. Aggressive Mode condenses the IKE SA negotiations into three packets (versus six packets for Main Mode). A group associates the same set of attributes to multiple clients. Use this setting to enable refresh and caching for IKE on remote APs. Select this button to add an IKE shared secret. The following settings appear. Complete these settings and click Add in this section.  Subnet-Enter the subnet for the shared secret.  Subnet Mask-Enter the subnet mask for the shared secret.  IKE Shared Secret-Type the shared secret, and confirm. Select this button to add a new IKE policy. The following settings appear. Complete these settings and click Add in this section.  Priority-Type the priority number of this IKE policy.  Encryption-From the drop-down menu, select the encryption type to be supported in the IKE policy.  Hash Algorithm-Select the hash algorithm for this IKE policy.  Authentication-Select the authentication type to be supported in this IKE policy.  Diffie-Hellman Group-Select the bit-level to be supported.  Lifetime (300-86400 sec)-Define the lifetime, in seconds, for the IKE policy. Once one or more policies are added, select the policy to apply to the VPN Services > IKE profile being configured. Select Add to create the VPN Services > IKE profile, or click Save to retain the changes to an existing IKE profile. The profile appears on the Advanced Services > VPN Services > IKE page. Advanced Services > VPN Services > L2TP The combination of Layer-2 Tunneling Protocol and Internet Protocol Security (L2TP/IPSec) is a highly secure technology that enables VPN connections across public networks such as the Internet. L2TP/IPSec provides both a logical transport mechanism on which to transmit PPP frames as well as tunneling or encapsulation so that the Dell PowerConnect W AirWave 7.2 | Configuration Guide Dell PowerConnect W Configuration Reference | 153

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160

Dell PowerConnect W AirWave 7.2
| Configuration Guide
Dell PowerConnect W Configuration Reference
|
153
IKE is a part of the IPSEC protocol suite, supporting security for VPNs with a shared session secret that produces
security keys.
Select
Add
to create a new IKE profile, or click the pencil icon next to an existing profile to edit.
Table 78
describes the fields on the
Advanced Services > VPN Services > IKE Add/Edit Detail
page.
Select
Add
to create the
VPN Services > IKE
profile, or click
Save
to retain the changes to an existing IKE
profile. The profile appears on the
Advanced Services > VPN Services > IKE
page.
Advanced Services > VPN Services > L2TP
The combination of Layer-2 Tunneling Protocol and Internet Protocol Security (L2TP/IPSec) is a highly secure
technology that enables VPN connections across public networks such as the Internet. L2TP/IPSec provides both
a logical transport mechanism on which to transmit PPP frames as well as tunneling or encapsulation so that the
NOTE:
The IKE profile requires the controller to have a Remote Access Points license or a VPN Server license.
Table 78
Advanced Services > VPN Services > IKE Add/Edit Detail Field Descriptions
Field
Default
Description
General Settings
Folder
Top
Set the folder with which the IKE profile is associated. The drop-down menu displays
all folders available for association with the IKE services profile.
Name
Blank
Enter the name of the IKE profile.
Other Settings
IKE Aggressive Group
Name
Enter the authentication group name for aggressive mode. Make sure that the group
name matches the group name configured in the VPN client software. Aggressive
Mode condenses the IKE SA negotiations into three packets (versus six packets for
Main Mode). A group associates the same set of attributes to multiple clients.
Enable IKE RAP PSKL
Refresh/Caching
No
Use this setting to enable refresh and caching for IKE on remote APs.
IKE Shared Secrets
Add
Select this button to add an IKE shared secret. The following settings appear.
Complete these settings and click
Add
in this section.
Subnet
—Enter the subnet for the shared secret.
Subnet Mask
—Enter the subnet mask for the shared secret.
IKE Shared Secret
—Type the shared secret, and confirm.
IKE Policies
Add
Select this button to add a new IKE policy. The following settings appear. Complete
these settings and click
Add
in this section.
Priority
—Type the priority number of this IKE policy.
Encryption
—From the drop-down menu, select the encryption type to be
supported in the IKE policy.
Hash Algorithm
—Select the hash algorithm for this IKE policy.
Authentication
—Select the authentication type to be supported in this IKE policy.
Diffie-Hellman Group
—Select the bit-level to be supported.
Lifetime
(300-86400 sec)—Define the lifetime, in seconds, for the IKE policy.
Once one or more policies are added, select the policy to apply to the
VPN Services >
IKE
profile being configured.