<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX 535 x aes in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-535-x-aes/m-p/458975#M557231</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does the 535-506E not initialize the VPN, or just not pass the traffic?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Verify that all Pix's have the same IKE Policies and IPSec transform sets.  Also verify that the IKE Policies have the same priority.  I'm assuming the IPSec priorities are ok if it works with DES.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the IKE policies match, but IPSec transform sets do not, the VPN can be initialized, but the traffic will fail.  Verify the existing IKE (Phase 1) tunnels by using 'sh cry is sa'.  A healthy tunnel should be in 'QM_IDLE' mode.  Verify IPSec (Phase 2) by using 'sh cry ip sa'.  This will show you the number of sent, received, and error packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note- I've been very happy with AES-128.  AES-256 killed system resources on 501 and 506s.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 15 Jun 2005 19:22:50 GMT</pubDate>
    <dc:creator>pkinzel</dc:creator>
    <dc:date>2005-06-15T19:22:50Z</dc:date>
    <item>
      <title>PIX 535 x aes</title>
      <link>https://community.cisco.com/t5/network-security/pix-535-x-aes/m-p/458974#M557229</link>
      <description>&lt;P&gt;I'm trying to migrate from DES to AES and my net has PIX 506E, 515 and 535. When the VPN is estabilished between 515-506E both side can initialize it. But between 535-506E only the 506E initialize the VPN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I return to DES the VPN works ok. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcelo&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:12:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-535-x-aes/m-p/458974#M557229</guid>
      <dc:creator>marcelo.rosas</dc:creator>
      <dc:date>2020-02-21T08:12:11Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 535 x aes</title>
      <link>https://community.cisco.com/t5/network-security/pix-535-x-aes/m-p/458975#M557231</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does the 535-506E not initialize the VPN, or just not pass the traffic?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Verify that all Pix's have the same IKE Policies and IPSec transform sets.  Also verify that the IKE Policies have the same priority.  I'm assuming the IPSec priorities are ok if it works with DES.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the IKE policies match, but IPSec transform sets do not, the VPN can be initialized, but the traffic will fail.  Verify the existing IKE (Phase 1) tunnels by using 'sh cry is sa'.  A healthy tunnel should be in 'QM_IDLE' mode.  Verify IPSec (Phase 2) by using 'sh cry ip sa'.  This will show you the number of sent, received, and error packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note- I've been very happy with AES-128.  AES-256 killed system resources on 501 and 506s.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Jun 2005 19:22:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-535-x-aes/m-p/458975#M557231</guid>
      <dc:creator>pkinzel</dc:creator>
      <dc:date>2005-06-15T19:22:50Z</dc:date>
    </item>
  </channel>
</rss>

