<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA Context config for S2S VPN in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-context-config-for-s2s-vpn/m-p/3365891#M975152</link>
    <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;it's been a while since i configured a new ASA with security contexts running.&lt;/P&gt;
&lt;P&gt;just a clarification on the 20-security context license i applied.&lt;/P&gt;
&lt;P&gt;is it good practice to use the max security license count under the VPN class using the command: &lt;STRONG&gt;limit-resource VPN Other &lt;FONT color="#FF0000"&gt;20&lt;/FONT&gt;&lt;/STRONG&gt;?&lt;/P&gt;
&lt;P&gt;do i also configure each context to be a member of VPN class so they can configure S2S IPsec VPN in their own context or will it be a good idea or good practice just to create a dedicated context for customer VPNs?&lt;/P&gt;
&lt;P&gt;i also see others configure a number or percent for IKEv1 in-negotiation. what is this for and what's a good value to input?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;/pri/act(config-class)# limit-resource VPN &lt;FONT color="#FF0000"&gt;ikev1 in-negotiation&lt;/FONT&gt; ?&lt;BR /&gt;&lt;BR /&gt;class mode commands/options:&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;&amp;nbsp; WORD&amp;nbsp; Value of resource limit (in &amp;lt;value&amp;gt; or &amp;lt;value&amp;gt;%)&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;---&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;lt;SYSTEM&amp;gt;&lt;BR /&gt;&lt;BR /&gt;class VPN&lt;BR /&gt;&amp;nbsp;&lt;FONT color="#FF0000"&gt;limit-resource VPN Other 20&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;context &amp;lt;CONTEXT-A&amp;gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;&amp;nbsp;member VPN&lt;/FONT&gt;&lt;BR /&gt;&amp;nbsp;allocate-interface GigabitEthernet0/0&lt;BR /&gt;&amp;nbsp;allocate-interface GigabitEthernet0/1.x&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;context &amp;lt;CONTEXT-B&amp;gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;&amp;nbsp;member VPN&lt;/FONT&gt;&lt;BR /&gt;&amp;nbsp;allocate-interface GigabitEthernet0/0&lt;BR /&gt;&amp;nbsp;allocate-interface GigabitEthernet0/1.x&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 15:38:00 GMT</pubDate>
    <dc:creator>johnlloyd_13</dc:creator>
    <dc:date>2020-02-21T15:38:00Z</dc:date>
    <item>
      <title>ASA Context config for S2S VPN</title>
      <link>https://community.cisco.com/t5/network-security/asa-context-config-for-s2s-vpn/m-p/3365891#M975152</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;it's been a while since i configured a new ASA with security contexts running.&lt;/P&gt;
&lt;P&gt;just a clarification on the 20-security context license i applied.&lt;/P&gt;
&lt;P&gt;is it good practice to use the max security license count under the VPN class using the command: &lt;STRONG&gt;limit-resource VPN Other &lt;FONT color="#FF0000"&gt;20&lt;/FONT&gt;&lt;/STRONG&gt;?&lt;/P&gt;
&lt;P&gt;do i also configure each context to be a member of VPN class so they can configure S2S IPsec VPN in their own context or will it be a good idea or good practice just to create a dedicated context for customer VPNs?&lt;/P&gt;
&lt;P&gt;i also see others configure a number or percent for IKEv1 in-negotiation. what is this for and what's a good value to input?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;/pri/act(config-class)# limit-resource VPN &lt;FONT color="#FF0000"&gt;ikev1 in-negotiation&lt;/FONT&gt; ?&lt;BR /&gt;&lt;BR /&gt;class mode commands/options:&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;&amp;nbsp; WORD&amp;nbsp; Value of resource limit (in &amp;lt;value&amp;gt; or &amp;lt;value&amp;gt;%)&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;---&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;lt;SYSTEM&amp;gt;&lt;BR /&gt;&lt;BR /&gt;class VPN&lt;BR /&gt;&amp;nbsp;&lt;FONT color="#FF0000"&gt;limit-resource VPN Other 20&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;context &amp;lt;CONTEXT-A&amp;gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;&amp;nbsp;member VPN&lt;/FONT&gt;&lt;BR /&gt;&amp;nbsp;allocate-interface GigabitEthernet0/0&lt;BR /&gt;&amp;nbsp;allocate-interface GigabitEthernet0/1.x&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;context &amp;lt;CONTEXT-B&amp;gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;&amp;nbsp;member VPN&lt;/FONT&gt;&lt;BR /&gt;&amp;nbsp;allocate-interface GigabitEthernet0/0&lt;BR /&gt;&amp;nbsp;allocate-interface GigabitEthernet0/1.x&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:38:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-context-config-for-s2s-vpn/m-p/3365891#M975152</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2020-02-21T15:38:00Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Context config for S2S VPN</title>
      <link>https://community.cisco.com/t5/network-security/asa-context-config-for-s2s-vpn/m-p/3366646#M975153</link>
      <description>I am also interested in any feedback about this thread.&lt;BR /&gt;I just enabled VPN for one context I was required to. My take was to edit the default class and give each context same values.&lt;BR /&gt;What I am not sure: what happens if I don't mention anything on the default class in regard to IKEv1 in-negotiation and VPN Burst.&lt;BR /&gt;&lt;BR /&gt;Thanks!</description>
      <pubDate>Mon, 16 Apr 2018 11:17:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-context-config-for-s2s-vpn/m-p/3366646#M975153</guid>
      <dc:creator>Florin Barhala</dc:creator>
      <dc:date>2018-04-16T11:17:14Z</dc:date>
    </item>
  </channel>
</rss>

