Campus AP IPSEC encryption option
11-10-2019 04:43 PM
We have controllers running on 6.5.4.x versions. All access points are CAP. For the IP sec tunnel between the AP and the controller, is it possible to change the phase 1 / 2 encryption encryption/hash alogrithm?
show crypto isakmp sa peer x.x.x.x
Phase1 Transform:EncrAlg:AES256 HashAlg:HMAC_SHA1_96
show crypto ipsec sa peer x.x.x.x
Phase2 Transform:Encryption Alg: AES 256 Authentication Alg: SHA1
Was told that the setting for the above are negotiated by the access points and cannot be changed manually. Was wondering if anyone was able to modify as the default hash is deem not so secure.
Re: Campus AP IPSEC encryption option
11-10-2019 04:59 PM
The Campus IPSEC encryption is only for control traffic to/from the AP. The user traffic is encrypted using whatever wireless protocol is configured and then tunneled via GRE. Which portion of the communication do you want to be more secure?
*Answers and views expressed by me on this forum are my own and not necessarily the position of Aruba Networks or Hewlett Packard Enterprise.*
ArubaOS 8.5 User Guide
InstantOS 8.5 User Guide
Airheads Video Knowledge Base
Remote Access Point Solution Guide
ArubaOS Consolidated Release Notes
ArubaOS 8 ViA VPN Solution Guide