cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2295
Views
10
Helpful
2
Replies

Ikev1 Using AH in IPSEC VPN configuration on ASA or Router questions

CiscoPurpleBelt
Level 6
Level 6

Which protocol suits or configs must you enter to build a IPSEC tunnel on ASA and use AH along with ESP? I understand you can use AH in conjunction with ESP but I don't know how you actually configure that or confirm it is being used on a IPSEC tunnel on a ASA or router.

1 Accepted Solution

Accepted Solutions

AH and ESP are both used to encapsulate the traffic, you can either use AH or ESP but not both at the sametime. It's highly unlikely you would want to use AH (Authenticated Header) it's not as secure as ESP (Encapsulated Security Payload). AH only authenticates the header, where as ESP authenticates the header and encrypts the data.

An easy way to determine which is in use on an active tunnel is to use the command "show crypto ipsec sa" you will then be able to determine whether you have AH or ESP SAs.

HTH

View solution in original post

2 Replies 2

balaji.bandi
Hall of Fame
Hall of Fame

i would strongly suggest to understand each one of them before you implementing..good old school document :

 

http://www.firewall.cx/networking-topics/protocols/870-ipsec-modes.html

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

AH and ESP are both used to encapsulate the traffic, you can either use AH or ESP but not both at the sametime. It's highly unlikely you would want to use AH (Authenticated Header) it's not as secure as ESP (Encapsulated Security Payload). AH only authenticates the header, where as ESP authenticates the header and encrypts the data.

An easy way to determine which is in use on an active tunnel is to use the command "show crypto ipsec sa" you will then be able to determine whether you have AH or ESP SAs.

HTH
Review Cisco Networking for a $25 gift card