<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Whats the difference between ikev2 and ipsec sa in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/whats-the-difference-between-ikev2-and-ipsec-sa/m-p/4752322#M1096626</link>
    <description>&lt;P&gt;friend it same only the IKE version different&lt;BR /&gt;dont confuse&lt;BR /&gt;show crypto ipsec sa &amp;lt;&amp;lt;- phase2 sa detail of IKEv1&lt;BR /&gt;show crypto ikev2 sa &amp;lt;&amp;lt;- phase2 sa detail of IKEv2&amp;nbsp;&lt;BR /&gt;there is no different at all.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 10 Jan 2023 17:42:07 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2023-01-10T17:42:07Z</dc:date>
    <item>
      <title>Whats the difference between ikev2 and ipsec sa</title>
      <link>https://community.cisco.com/t5/network-security/whats-the-difference-between-ikev2-and-ipsec-sa/m-p/4752299#M1096624</link>
      <description>&lt;H2 id="wp3114534247__GUID-C0C9BF57-06C6-4E7B-9D42-0AD9F2F80BD9" class="title topictitle2"&gt;Hi&lt;/H2&gt;
&lt;H2 class="title topictitle2"&gt;Whats the difference between following 2 commans&lt;/H2&gt;
&lt;H2 class="title topictitle2"&gt;show crypto ikev2 sa&lt;/H2&gt;
&lt;H2 id="wp3458936948__GUID-0CA2251A-5510-4F58-83A7-2ABF630946A2" class="title topictitle2"&gt;show crypto ipsec sa&lt;/H2&gt;</description>
      <pubDate>Tue, 10 Jan 2023 17:13:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/whats-the-difference-between-ikev2-and-ipsec-sa/m-p/4752299#M1096624</guid>
      <dc:creator>MSJ1</dc:creator>
      <dc:date>2023-01-10T17:13:07Z</dc:date>
    </item>
    <item>
      <title>Re: Whats the difference between ikev2 and ipsec sa</title>
      <link>https://community.cisco.com/t5/network-security/whats-the-difference-between-ikev2-and-ipsec-sa/m-p/4752313#M1096625</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1146335"&gt;@MSJ1&lt;/a&gt; the purpose of IKE (v1 or v2) is used to establish a secure communication channel (1 bidirectional SA) through which the IPSec SA is securely negotiated. Once the IPSec SAs (2 unidirectional SA) has been established, all data is securely transmitted over this IPSec VPN.&lt;/P&gt;
&lt;P&gt;So "show crypto ikev2 sa" represents the IKEv2 SA and "show crypto ipsec sa" represents the IPSec SAs.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2023 17:24:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/whats-the-difference-between-ikev2-and-ipsec-sa/m-p/4752313#M1096625</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-01-10T17:24:51Z</dc:date>
    </item>
    <item>
      <title>Re: Whats the difference between ikev2 and ipsec sa</title>
      <link>https://community.cisco.com/t5/network-security/whats-the-difference-between-ikev2-and-ipsec-sa/m-p/4752322#M1096626</link>
      <description>&lt;P&gt;friend it same only the IKE version different&lt;BR /&gt;dont confuse&lt;BR /&gt;show crypto ipsec sa &amp;lt;&amp;lt;- phase2 sa detail of IKEv1&lt;BR /&gt;show crypto ikev2 sa &amp;lt;&amp;lt;- phase2 sa detail of IKEv2&amp;nbsp;&lt;BR /&gt;there is no different at all.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2023 17:42:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/whats-the-difference-between-ikev2-and-ipsec-sa/m-p/4752322#M1096626</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-01-10T17:42:07Z</dc:date>
    </item>
    <item>
      <title>Re: Whats the difference between ikev2 and ipsec sa</title>
      <link>https://community.cisco.com/t5/network-security/whats-the-difference-between-ikev2-and-ipsec-sa/m-p/4752330#M1096627</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;friend it same,&amp;nbsp;&lt;BR /&gt;show crypto ipsec sa &amp;lt;&amp;lt;- phase2 sa detail of IKEv1&lt;BR /&gt;show crypto ikev2 sa &amp;lt;&amp;lt;- phase2 sa detail of IKEv2&amp;nbsp;&lt;BR /&gt;there is no different at all.&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;that's not correct. "show crypto ikev2 sa" is control plane (IKE) and "show crypto ipsec sa" is data plane (IPSec).&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2023 17:48:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/whats-the-difference-between-ikev2-and-ipsec-sa/m-p/4752330#M1096627</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-01-10T17:48:41Z</dc:date>
    </item>
    <item>
      <title>Re: Whats the difference between ikev2 and ipsec sa</title>
      <link>https://community.cisco.com/t5/network-security/whats-the-difference-between-ikev2-and-ipsec-sa/m-p/4752333#M1096628</link>
      <description>&lt;P&gt;so please give me what value appear in show crypto ipsec sa and not appear in&amp;nbsp; show crypto ikev2 sa.&lt;BR /&gt;I need to know.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2023 17:52:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/whats-the-difference-between-ikev2-and-ipsec-sa/m-p/4752333#M1096628</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-01-10T17:52:18Z</dc:date>
    </item>
    <item>
      <title>Re: Whats the difference between ikev2 and ipsec sa</title>
      <link>https://community.cisco.com/t5/network-security/whats-the-difference-between-ikev2-and-ipsec-sa/m-p/4752340#M1096629</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt; observe the difference in the output of those commands in this &lt;A href="https://integratingit.wordpress.com/2016/07/10/configuring-cisco-flexvpn-hub-and-spoke/" target="_self"&gt;post&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;"show crypto ikev1 sa" is the equivalent of "show crypto ikev2 sa" just using IKEv2 protocol, they perform the same task.&lt;/P&gt;
&lt;P&gt;Regardless of whether you are using IKEv1 or IKEv2 "show crypto ipsec sa" is the encrypted data plane, which would be negotiated with IKEv1 or IKEv2.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2023 18:07:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/whats-the-difference-between-ikev2-and-ipsec-sa/m-p/4752340#M1096629</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-01-10T18:07:01Z</dc:date>
    </item>
    <item>
      <title>Re: Whats the difference between ikev2 and ipsec sa</title>
      <link>https://community.cisco.com/t5/network-security/whats-the-difference-between-ikev2-and-ipsec-sa/m-p/4752343#M1096630</link>
      <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/security/s1/sec-s1-cr-book/sec-cr-s3.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/security/s1/sec-s1-cr-book/sec-cr-s3.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;this command reference, I dont see show crypto ikev1 sa !!!&lt;BR /&gt;or I am wrong ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2023 18:16:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/whats-the-difference-between-ikev2-and-ipsec-sa/m-p/4752343#M1096630</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-01-10T18:16:41Z</dc:date>
    </item>
    <item>
      <title>Re: Whats the difference between ikev2 and ipsec sa</title>
      <link>https://community.cisco.com/t5/network-security/whats-the-difference-between-ikev2-and-ipsec-sa/m-p/4752346#M1096632</link>
      <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/5409-ipsec-debug-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/5409-ipsec-debug-00.html&lt;/A&gt;&lt;BR /&gt;this link also there is no show crypto ikev1 sa, instead you can use show crypto ipsec sa &amp;lt;&amp;lt;- this give detail about phase2 of IKE.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2023 18:18:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/whats-the-difference-between-ikev2-and-ipsec-sa/m-p/4752346#M1096632</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-01-10T18:18:48Z</dc:date>
    </item>
    <item>
      <title>Re: Whats the difference between ikev2 and ipsec sa</title>
      <link>https://community.cisco.com/t5/network-security/whats-the-difference-between-ikev2-and-ipsec-sa/m-p/4752349#M1096633</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt; "show crypto ikev1 sa" is the syntax for ASA/FTD - &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa-cli-reference/S/asa-command-ref-S/show-cr-to-show-cz-commands.html#wp1242471814" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa-cli-reference/S/asa-command-ref-S/show-cr-to-show-cz-commands.html#wp1242471814&lt;/A&gt; - On IOS routers you use isakmp in place of IKEv1 to display the IKEv1 SA.&lt;/P&gt;
&lt;P&gt;IKEv2 - &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa-cli-reference/S/asa-command-ref-S/show-cr-to-show-cz-commands.html#wp4061035436" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa-cli-reference/S/asa-command-ref-S/show-cr-to-show-cz-commands.html#wp4061035436&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;IPSec SA - &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa-cli-reference/S/asa-command-ref-S/show-cr-to-show-cz-commands.html#wp4192597247" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa-cli-reference/S/asa-command-ref-S/show-cr-to-show-cz-commands.html#wp4192597247&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2023 18:25:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/whats-the-difference-between-ikev2-and-ipsec-sa/m-p/4752349#M1096633</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-01-10T18:25:00Z</dc:date>
    </item>
    <item>
      <title>Re: Whats the difference between ikev2 and ipsec sa</title>
      <link>https://community.cisco.com/t5/network-security/whats-the-difference-between-ikev2-and-ipsec-sa/m-p/4752353#M1096634</link>
      <description>&lt;P&gt;Yes now we talk,&amp;nbsp;&lt;BR /&gt;what we want to know from phase 2 is local/remote proxy and SPI for inbound/outbound&amp;nbsp;&lt;BR /&gt;IKEv1&amp;nbsp;&lt;/P&gt;&lt;P&gt;show crypto isakmp sa &amp;lt;&amp;lt;- phase1&amp;nbsp;&lt;BR /&gt;show crypto ipsec sa &amp;lt;&amp;lt;- phase 2&lt;BR /&gt;&lt;BR /&gt;IKEv2&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;show crypto ikev2 sa &amp;lt;&amp;lt;- &lt;FONT color="#00FF00"&gt;&lt;STRONG&gt;phase1&lt;/STRONG&gt;&lt;/FONT&gt; &amp;amp; phase2 (phase2 because it can show us &lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;SPI and local/remote proxy&lt;/FONT&gt;&lt;/STRONG&gt; )&lt;BR /&gt;show crypto ipsec sa &amp;lt;&amp;lt;- phase2 BUT I want to mention that it can show packet encrypt/decrypt count.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2023 19:38:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/whats-the-difference-between-ikev2-and-ipsec-sa/m-p/4752353#M1096634</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-01-10T19:38:47Z</dc:date>
    </item>
    <item>
      <title>Re: Whats the difference between ikev2 and ipsec sa</title>
      <link>https://community.cisco.com/t5/network-security/whats-the-difference-between-ikev2-and-ipsec-sa/m-p/4752396#M1096637</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;why do they have different DH group 5 and 14 for ikev2 sa and ipsec sa command&amp;nbsp; ?&lt;/P&gt;
&lt;P&gt;FW# show crypto ikev2 sa&lt;/P&gt;
&lt;P&gt;IKEv2 SAs:&lt;/P&gt;
&lt;P&gt;Session-id:2, Status:UP-ACTIVE, IKE count:1, CHILD count:2&lt;/P&gt;
&lt;P&gt;Tunnel-id Local Remote Status Role&lt;/P&gt;
&lt;P&gt;1063293681 Head_End_IP/500 Remote_Head_End_IP/500 READY INITIATOR\&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Encr: AES-CBC, keysize: 256, Hash: SHA96, DH Grp:5, Auth sign: PSK, Auth verify: PSK&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Life/Active Time: 86400/69018 sec&lt;BR /&gt;Child sa: local selector 10.XX.XXX.0/0 - 10.XX.XXX.255/65535&lt;BR /&gt;remote selector 0.0.0.0/0 - 255.255.255.255/65535&lt;BR /&gt;ESP spi in/out: 0x77595683/0x5d6f8285&lt;/P&gt;
&lt;P&gt;Child sa: local selector YY.YY.YY.YY/0 - YY.YY.YY.YY/65535&lt;BR /&gt;remote selector XX.XX.XX.XX/0 - XX.XX.XX.XX/65535&lt;/P&gt;
&lt;P&gt;ESP spi in/out: 0xaca7647e/0xb091149b&lt;/P&gt;
&lt;P&gt;==========================================================&lt;/P&gt;
&lt;P&gt;FW# show crypto ipsec sa&lt;BR /&gt;interface: outside&lt;BR /&gt;Crypto map tag: outside_map, seq num: 1, local addr: XXXXXXXXX&lt;/P&gt;
&lt;P&gt;access-list outside_cryptomap extended permit ip XXXXXX 255.255.255.0 any4&lt;BR /&gt;local ident (addr/mask/prot/port): (XXXXXX/255.255.255.0/0/0)&lt;BR /&gt;remote ident (addr/mask/prot/port): (0.0.0.0/0.0.0.0/0/0)&lt;BR /&gt;current_peer: XXXXXXXX&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;#pkts encaps: 67753167, #pkts encrypt: 67673173, #pkts digest: 67673173&lt;BR /&gt;#pkts decaps: 123372327, #pkts decrypt: 123372327, #pkts verify: 123372327&lt;BR /&gt;#pkts compressed: 0, #pkts decompressed: 0&lt;BR /&gt;#pkts not compressed: 67753170, #pkts comp failed: 0, #pkts decomp failed: 0&lt;BR /&gt;#pre-frag successes: 0, #pre-frag failures: 79992, #fragments created: 0&lt;BR /&gt;#PMTUs sent: 79992, #PMTUs rcvd: 0, #decapsulated frgs needing reassembly: 0&lt;BR /&gt;#TFC rcvd: 0, #TFC sent: 0&lt;BR /&gt;#Valid ICMP Errors rcvd: 0, #Invalid ICMP Errors rcvd: 0&lt;BR /&gt;#send errors: 1, #recv errors: 26&lt;/P&gt;
&lt;P&gt;local crypto endpt.: XXXX/500, remote crypto endpt.: XXXX/500&lt;BR /&gt;path mtu 1500, ipsec overhead 78(44), media mtu 1500&lt;BR /&gt;PMTU time remaining (sec): 0, DF policy: copy-df&lt;BR /&gt;ICMP error validation: disabled, TFC packets: disabled&lt;BR /&gt;current outbound spi: 5D6F8285&lt;BR /&gt;current inbound spi : 77595683&lt;/P&gt;
&lt;P&gt;inbound esp sas:&lt;BR /&gt;spi: 0x77595683 (2002343555)&lt;BR /&gt;SA State: active&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;transform: esp-aes-256 esp-sha-256-hmac no compression&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;in use settings ={L2L, Tunnel, PFS Group 14, IKEv2, }&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;slot: 0, conn_id: 26, crypto-map: outside_map&lt;BR /&gt;sa timing: remaining key lifetime (kB/sec): (4236342/28327)&lt;BR /&gt;IV size: 16 bytes&lt;BR /&gt;replay detection support: Y&lt;BR /&gt;Anti replay bitmap:&lt;BR /&gt;0xFFFFFFFF 0xFFFFFFFF&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;outbound esp sas:&lt;BR /&gt;spi: 0x5D6F8285 (1567588997)&lt;BR /&gt;SA State: active&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;transform: esp-aes-256 esp-sha-256-hmac no compression&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;in use settings ={L2L, Tunnel, PFS Group 14, IKEv2, }&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;slot: 0, conn_id: 26, crypto-map: outside_map&lt;BR /&gt;sa timing: remaining key lifetime (kB/sec): (4006416/28327)&lt;BR /&gt;IV size: 16 bytes&lt;BR /&gt;replay detection support: Y&lt;BR /&gt;Anti replay bitmap:&lt;BR /&gt;0x00000000 0x00000001&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2023 19:30:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/whats-the-difference-between-ikev2-and-ipsec-sa/m-p/4752396#M1096637</guid>
      <dc:creator>MSJ1</dc:creator>
      <dc:date>2023-01-10T19:30:51Z</dc:date>
    </item>
    <item>
      <title>Re: Whats the difference between ikev2 and ipsec sa</title>
      <link>https://community.cisco.com/t5/network-security/whats-the-difference-between-ikev2-and-ipsec-sa/m-p/4752397#M1096638</link>
      <description>&lt;P&gt;because the IKEv2 can use two DH group&amp;nbsp;&lt;BR /&gt;one group of phase1 DH =5&amp;nbsp;&lt;BR /&gt;other group of phase 2 DH=14 with PFS&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2023 19:33:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/whats-the-difference-between-ikev2-and-ipsec-sa/m-p/4752397#M1096638</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-01-10T19:33:06Z</dc:date>
    </item>
  </channel>
</rss>

