<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN L2L - Explicit Phase 1 SA settings in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/vpn-l2l-explicit-phase-1-sa-settings/m-p/926668#M937881</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;  If I understand your request correctly, I think you just need to configure an IKE poicy and give it the higher priority (lower number )  than the existing policies, by that you will be sure that this policy will be used first, and by the way if the IKE policy will match only identical IKE policy at your side, so regardless the priority of this policy, it will be matched.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;example of IKE policy for this :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;isakmp policy 1 ecncr aes&lt;/P&gt;&lt;P&gt;isakmp policy 1 auth pre-share&lt;/P&gt;&lt;P&gt;isakmp policy 1 hash sha&lt;/P&gt;&lt;P&gt;isakmp policy 1 group 2  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; hope its helpful&lt;/P&gt;&lt;P&gt;with regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 13 May 2008 13:13:49 GMT</pubDate>
    <dc:creator>alanajjar</dc:creator>
    <dc:date>2008-05-13T13:13:49Z</dc:date>
    <item>
      <title>VPN L2L - Explicit Phase 1 SA settings</title>
      <link>https://community.cisco.com/t5/network-security/vpn-l2l-explicit-phase-1-sa-settings/m-p/926667#M937879</link>
      <description>&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was wondering, is it possible to explicitly set the IKE SA policy through the tunnel group settings? My understanding is the first isakmp policy that matches on both ends is the selected one. &lt;/P&gt;&lt;P&gt;I want to make sure the SA settings I gave to the other company are the one we told them without impacting any other existing VPN tunnels.&lt;/P&gt;&lt;P&gt;To be more expliciti want to make sure, encryption aes, hash sha,DH group 2, are the settings that will be used and nothing else. All this without removing existing isakmp policies (if possible).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:43:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-l2l-explicit-phase-1-sa-settings/m-p/926667#M937879</guid>
      <dc:creator>deephazz02</dc:creator>
      <dc:date>2019-03-11T12:43:42Z</dc:date>
    </item>
    <item>
      <title>Re: VPN L2L - Explicit Phase 1 SA settings</title>
      <link>https://community.cisco.com/t5/network-security/vpn-l2l-explicit-phase-1-sa-settings/m-p/926668#M937881</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;  If I understand your request correctly, I think you just need to configure an IKE poicy and give it the higher priority (lower number )  than the existing policies, by that you will be sure that this policy will be used first, and by the way if the IKE policy will match only identical IKE policy at your side, so regardless the priority of this policy, it will be matched.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;example of IKE policy for this :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;isakmp policy 1 ecncr aes&lt;/P&gt;&lt;P&gt;isakmp policy 1 auth pre-share&lt;/P&gt;&lt;P&gt;isakmp policy 1 hash sha&lt;/P&gt;&lt;P&gt;isakmp policy 1 group 2  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; hope its helpful&lt;/P&gt;&lt;P&gt;with regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 May 2008 13:13:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-l2l-explicit-phase-1-sa-settings/m-p/926668#M937881</guid>
      <dc:creator>alanajjar</dc:creator>
      <dc:date>2008-05-13T13:13:49Z</dc:date>
    </item>
    <item>
      <title>Re: VPN L2L - Explicit Phase 1 SA settings</title>
      <link>https://community.cisco.com/t5/network-security/vpn-l2l-explicit-phase-1-sa-settings/m-p/926669#M937883</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually that is almost what I want to do.&lt;/P&gt;&lt;P&gt;I was wondering if there is a way to assign a isakmp policy to a tunnel group or a crypto map but more likely to a tunnel group.Because if I modify the priority of the isakmp policy then i will influence all the vpn going through phase 1 that will potentially match first the policy with a higher priority. So at then I could en up with phase 1 settings changed for existing vpns.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 May 2008 15:56:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-l2l-explicit-phase-1-sa-settings/m-p/926669#M937883</guid>
      <dc:creator>deephazz02</dc:creator>
      <dc:date>2008-05-13T15:56:34Z</dc:date>
    </item>
  </channel>
</rss>

