Wireless Access

Occasional Contributor I

Campus AP IPSEC encryption option

We have controllers running on 6.5.4.x versions. All access points are CAP. For the IP sec tunnel between the AP and the controller, is it possible to change the phase 1 / 2 encryption encryption/hash alogrithm?


For eg.

show crypto isakmp sa peer x.x.x.x

Phase1 Transform:EncrAlg:AES256 HashAlg:HMAC_SHA1_96


show crypto ipsec sa peer x.x.x.x

Phase2 Transform:Encryption Alg: AES 256 Authentication Alg: SHA1


Was told that the setting for the above are negotiated by the access points and cannot be changed manually. Was wondering if anyone was able to modify as the default hash is deem not so secure.

Guru Elite

Re: Campus AP IPSEC encryption option

The Campus IPSEC encryption is only for control traffic to/from the AP.  The user traffic is encrypted using whatever wireless protocol is configured and then tunneled via GRE.  Which portion of the communication do you want to be more secure?

*Answers and views expressed by me on this forum are my own and not necessarily the position of Aruba Networks or Hewlett Packard Enterprise.*
ArubaOS 8.5 User Guide
InstantOS 8.5 User Guide
Airheads Knowledgebase
Airheads Video Knowledge Base
Remote Access Point Solution Guide
ArubaOS Consolidated Release Notes
ArubaOS 8 ViA VPN Solution Guide
Occasional Contributor I

Re: Campus AP IPSEC encryption option

Looking to change the encypriton between the AP and the controller to more secure algorithm but am not sure if that is possible.

Search Airheads
Showing results for 
Search instead for 
Did you mean: