<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ikev2 Ipsec Between Asa and Sonicwall in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ikev2-ipsec-between-asa-and-sonicwall/m-p/4277818#M1077578</link>
    <description>&lt;LI-SPOILER&gt;&amp;nbsp;&lt;/LI-SPOILER&gt;&lt;P&gt;Yes, i also thought the same. But the other end engineer was also shocked as he was using regularly a sonicwall firewall and he was never heard about prf in phase 1 and when i told him if there is any advance setting in sonic wall where he can check this prf he said no only this much setting he was aware about phase 1. he told also if he will change from ikev2 to mainmode he will get prf option for phase 1 in sonic wall&lt;/P&gt;</description>
    <pubDate>Fri, 22 Jan 2021 18:51:11 GMT</pubDate>
    <dc:creator>SajeshB</dc:creator>
    <dc:date>2021-01-22T18:51:11Z</dc:date>
    <item>
      <title>Ikev2 Ipsec Between Asa and Sonicwall</title>
      <link>https://community.cisco.com/t5/network-security/ikev2-ipsec-between-asa-and-sonicwall/m-p/4277800#M1077575</link>
      <description>&lt;P&gt;Hi team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Need help in understanding an issue faced when creating a tunnel between Asa and Sonicwall (Issue got resolved) still need help to understand.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SonicWall: Phase 1&lt;/P&gt;&lt;P&gt;Ikev2&lt;/P&gt;&lt;P&gt;Encryption aes&lt;/P&gt;&lt;P&gt;Authentication sha265&lt;/P&gt;&lt;P&gt;Dh 14&lt;/P&gt;&lt;P&gt;Lifetime 86400&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Asa: phase 1&lt;/P&gt;&lt;P&gt;Ikev2&amp;nbsp;&lt;/P&gt;&lt;P&gt;Encryption aes&lt;/P&gt;&lt;P&gt;Integrity sha256&lt;/P&gt;&lt;P&gt;Dh 15&lt;/P&gt;&lt;P&gt;Prf sha&lt;/P&gt;&lt;P&gt;Lifetime 86400&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As the issue was with the asa end. The prf was bydefault configured in ikev2 and i i cannot remove that but after changing prf sha to sha256 tunnel come up. Can anyone help me to understand why tunnel come up while changing the prf value i thought either i need to remove that from config or else changing the ikev2 mode to ikve1.&lt;/P&gt;&lt;P&gt;And one more additional thing sonicwall authentication is similar to cisco integrity attribute if im not wrong.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2021 18:18:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ikev2-ipsec-between-asa-and-sonicwall/m-p/4277800#M1077575</guid>
      <dc:creator>SajeshB</dc:creator>
      <dc:date>2021-01-22T18:18:14Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Ipsec Between Asa and Sonicwall</title>
      <link>https://community.cisco.com/t5/network-security/ikev2-ipsec-between-asa-and-sonicwall/m-p/4277807#M1077576</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1039108"&gt;@SajeshB&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;IKE configuration needs to match between peers, it sounds like the Sonicwall was configured with a default prf value of SHA256 and changing the ASA's default value from SHA to SHA256 obviously made the settings match and establish connectivity.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2021 18:26:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ikev2-ipsec-between-asa-and-sonicwall/m-p/4277807#M1077576</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2021-01-22T18:26:56Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Ipsec Between Asa and Sonicwall</title>
      <link>https://community.cisco.com/t5/network-security/ikev2-ipsec-between-asa-and-sonicwall/m-p/4277818#M1077578</link>
      <description>&lt;LI-SPOILER&gt;&amp;nbsp;&lt;/LI-SPOILER&gt;&lt;P&gt;Yes, i also thought the same. But the other end engineer was also shocked as he was using regularly a sonicwall firewall and he was never heard about prf in phase 1 and when i told him if there is any advance setting in sonic wall where he can check this prf he said no only this much setting he was aware about phase 1. he told also if he will change from ikev2 to mainmode he will get prf option for phase 1 in sonic wall&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2021 18:51:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ikev2-ipsec-between-asa-and-sonicwall/m-p/4277818#M1077578</guid>
      <dc:creator>SajeshB</dc:creator>
      <dc:date>2021-01-22T18:51:11Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Ipsec Between Asa and Sonicwall</title>
      <link>https://community.cisco.com/t5/network-security/ikev2-ipsec-between-asa-and-sonicwall/m-p/4277826#M1077579</link>
      <description>&lt;P&gt;This is probably a question that should be posed to Sonicwall TAC. I imagine that on the Sonicwall the PRF value is automatically set to the same as the integrity value, in your instance SHA256. The fact that on the ASA you had to change the value from SHA to SHA256 in order to get the VPN to establish, indicates that the Sonicwall is using PRF with SHA256, otherwise it would not have worked.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2021 19:07:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ikev2-ipsec-between-asa-and-sonicwall/m-p/4277826#M1077579</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2021-01-22T19:07:22Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Ipsec Between Asa and Sonicwall</title>
      <link>https://community.cisco.com/t5/network-security/ikev2-ipsec-between-asa-and-sonicwall/m-p/4277840#M1077580</link>
      <description>&lt;P&gt;Thanx Rob, i thought i was wrong with my config seems to be an issue with the other end.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2021 19:18:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ikev2-ipsec-between-asa-and-sonicwall/m-p/4277840#M1077580</guid>
      <dc:creator>SajeshB</dc:creator>
      <dc:date>2021-01-22T19:18:14Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Ipsec Between Asa and Sonicwall</title>
      <link>https://community.cisco.com/t5/network-security/ikev2-ipsec-between-asa-and-sonicwall/m-p/4415556#M1081405</link>
      <description>&lt;P&gt;Right zaid i have tested this on my lab and then I experienced how sonicwall IPSEC works. But if we see from ASA side then prf and integrity have similar function for authenticate messages might be they need to be same. So the same config I have tested for ASA and palo alto and it works.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jun 2021 15:39:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ikev2-ipsec-between-asa-and-sonicwall/m-p/4415556#M1081405</guid>
      <dc:creator>SajeshB</dc:creator>
      <dc:date>2021-06-09T15:39:00Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Ipsec Between Asa and Sonicwall</title>
      <link>https://community.cisco.com/t5/network-security/ikev2-ipsec-between-asa-and-sonicwall/m-p/5197236#M1115989</link>
      <description>&lt;P&gt;&lt;A href="https://community.cisco.com/" target="_self"&gt;Nice Artcle&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Thanks for Sharining With Us&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Sep 2024 07:26:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ikev2-ipsec-between-asa-and-sonicwall/m-p/5197236#M1115989</guid>
      <dc:creator>shekarnaidu520</dc:creator>
      <dc:date>2024-09-22T07:26:14Z</dc:date>
    </item>
  </channel>
</rss>

