<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA: IKEv1 AND IKEv2 tunnels on the same context? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-ikev1-and-ikev2-tunnels-on-the-same-context/m-p/5036577#M1109739</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/96014"&gt;@swscco001&lt;/a&gt; you can run both IKEv1 and IKEv2 in parallel without problem in single mode, I don't see a problem either if using multi-context mode.&lt;/P&gt;</description>
    <pubDate>Fri, 08 Mar 2024 14:00:53 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2024-03-08T14:00:53Z</dc:date>
    <item>
      <title>ASA: IKEv1 AND IKEv2 tunnels on the same context?</title>
      <link>https://community.cisco.com/t5/network-security/asa-ikev1-and-ikev2-tunnels-on-the-same-context/m-p/5036574#M1109738</link>
      <description>&lt;P&gt;Hello everybody,&lt;BR /&gt;&lt;BR /&gt;a customer has a ASA5516-X running 9.16(4) with two contexts. He is using one&lt;BR /&gt;context for remote access by AnyConnect with IKEv2. The other context was used&lt;BR /&gt;just for&amp;nbsp;IKEv1 tunnels until now.&lt;BR /&gt;&lt;BR /&gt;Now he need to start to convert&amp;nbsp;IKEv1 to IKEv2 tunnels if possible. So he will&lt;BR /&gt;have&amp;nbsp;IKEv1 AND IKEv2 tunnels on the same context.&lt;BR /&gt;&lt;BR /&gt;Is there any we need to keep in mind or is there a known bug that is against this &lt;BR /&gt;change project?&lt;BR /&gt;&lt;BR /&gt;Every hint is welcome!&lt;BR /&gt;&lt;BR /&gt;Thanks a lot and have a nice weekend!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Bye&lt;BR /&gt;R.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2024 13:53:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ikev1-and-ikev2-tunnels-on-the-same-context/m-p/5036574#M1109738</guid>
      <dc:creator>swscco001</dc:creator>
      <dc:date>2024-03-08T13:53:51Z</dc:date>
    </item>
    <item>
      <title>Re: ASA: IKEv1 AND IKEv2 tunnels on the same context?</title>
      <link>https://community.cisco.com/t5/network-security/asa-ikev1-and-ikev2-tunnels-on-the-same-context/m-p/5036577#M1109739</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/96014"&gt;@swscco001&lt;/a&gt; you can run both IKEv1 and IKEv2 in parallel without problem in single mode, I don't see a problem either if using multi-context mode.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2024 14:00:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ikev1-and-ikev2-tunnels-on-the-same-context/m-p/5036577#M1109739</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-03-08T14:00:53Z</dc:date>
    </item>
    <item>
      <title>Re: ASA: IKEv1 AND IKEv2 tunnels on the same context?</title>
      <link>https://community.cisco.com/t5/network-security/asa-ikev1-and-ikev2-tunnels-on-the-same-context/m-p/5036597#M1109740</link>
      <description>&lt;P&gt;convert from IKEv1 to IKEv2,&lt;/P&gt;
&lt;P&gt;I.e. both protect same subnet ? if Yes then there is issue, you need to use either IKEv1 or IKEv2&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2024 14:39:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ikev1-and-ikev2-tunnels-on-the-same-context/m-p/5036597#M1109740</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-03-08T14:39:08Z</dc:date>
    </item>
    <item>
      <title>Re: ASA: IKEv1 AND IKEv2 tunnels on the same context?</title>
      <link>https://community.cisco.com/t5/network-security/asa-ikev1-and-ikev2-tunnels-on-the-same-context/m-p/5036621#M1109741</link>
      <description>&lt;P&gt;You can run IKEv1 and IKEv2 on the same crypto map, IKEv2 would be preferred but can fail back to IKEv1.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2024 15:17:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ikev1-and-ikev2-tunnels-on-the-same-context/m-p/5036621#M1109741</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-03-08T15:17:18Z</dc:date>
    </item>
    <item>
      <title>Re: ASA: IKEv1 AND IKEv2 tunnels on the same context?</title>
      <link>https://community.cisco.com/t5/network-security/asa-ikev1-and-ikev2-tunnels-on-the-same-context/m-p/5036633#M1109742</link>
      <description>&lt;P&gt;I will run lab my friend and share result here.&lt;/P&gt;
&lt;P&gt;If you have other points to check in lab please share it&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2024 15:48:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ikev1-and-ikev2-tunnels-on-the-same-context/m-p/5036633#M1109742</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-03-08T15:48:53Z</dc:date>
    </item>
    <item>
      <title>Re: ASA: IKEv1 AND IKEv2 tunnels on the same context?</title>
      <link>https://community.cisco.com/t5/network-security/asa-ikev1-and-ikev2-tunnels-on-the-same-context/m-p/5036950#M1109754</link>
      <description>&lt;P&gt;the IKEv1 have seq 5 and IKEv2 have seq 10&lt;/P&gt;
&lt;P&gt;the IPSec VPN is build without check IKEv2&amp;nbsp;&lt;BR /&gt;note:- again this in case your same LAN is protect by both IKEv1/v2&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot (167).png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/212100i67E4FABF8A5D4CBD/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot (167).png" alt="Screenshot (167).png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot (168).png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/212099i3B8A0179EFA7B571/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot (168).png" alt="Screenshot (168).png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 09 Mar 2024 18:56:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ikev1-and-ikev2-tunnels-on-the-same-context/m-p/5036950#M1109754</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-03-09T18:56:31Z</dc:date>
    </item>
    <item>
      <title>Re: ASA: IKEv1 AND IKEv2 tunnels on the same context?</title>
      <link>https://community.cisco.com/t5/network-security/asa-ikev1-and-ikev2-tunnels-on-the-same-context/m-p/5037102#M1109758</link>
      <description>&lt;P&gt;just to add in my bit. My understanding about reading your question.&lt;/P&gt;
&lt;P&gt;ASA5516-X running 9.16(4) with two contexts. One context running IKEv2 anyconnect and the other context running IKEv1 tunnel. Now the customer want to migrate IKEv1 tunnel to IKEv2.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa916/configuration/general/asa-916-general-config/ha-contexts.html?bookSearch=true " target="_self"&gt;ASA vpn multi-context support&lt;/A&gt; in version 9.16.x. Customer would be fine migrating from tunnel IKEv1 to IKEv2. Just tell them to do the prep-configuration prior to switchover. (having said Rob already mentioned the prefference would be IKEv2). &lt;A href="http://tunnel-group 195.59.115.220 ipsec-attributes  ikev1 pre-shared-key *****  peer-id-validate req  no chain  no ikev1 trust-point  isakmp keepalive threshold 10 retry 2  no ikev2 remote-authentication  no ikev2 local-authentication" target="_self"&gt;Swift Migration of IKEv1 to IKEv2 L2L Tunnel&lt;/A&gt; This is an old document but still very relevent today.&lt;/P&gt;
&lt;P&gt;I suggest if customer or youself making these changes in change window ask your third party/remote side to switch to ikev2 as your ASA will automatially switchoff to ikev2 from ikev1. In case if this does not happens issue this command where ikev1 tunnel resides.&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;vpn-sessiondb logoff tunnel-group 1.1.1.1 noconfirm&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2024 11:49:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ikev1-and-ikev2-tunnels-on-the-same-context/m-p/5037102#M1109758</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2024-03-10T11:49:33Z</dc:date>
    </item>
  </channel>
</rss>

