cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1630
Views
0
Helpful
1
Replies

VPN controllers in 3640's and 2611's: Authentication options.

aarsenault
Level 1
Level 1

Original configuration was one 3640 connecting to 2 2611's using IPSEC using software alone. ISAKMP authentication was by rsa-encr. Was found to be too slow. one nm-vpn/mp and 2 aim-vpn/bp were purchased. Apparently the nodes now can only authenticate with pre-shared keys. Are there any other options for isakmp authentication, such as x.509 certificates? Lots of documentation is available but hardly any for these cards. Some seems contradictory. need straight answer.

Thank you

1 Reply 1

awaheed
Cisco Employee
Cisco Employee

Hi,

You can use the Pre-shared keys aswell as the Certificates options with these cards, what these cards are merely doing is to get your Encryption speeded up, moving it from Software encryption over to Hardware encryption.

You can look at the following link for details on what your options are:

http://www.cisco.com/warp/customer/707/ios_meshed.html

http://www.cisco.com/warp/customer/707/mult-id-ca.html

Hope this helps,

Thanks and Regards,

Aamir Waheed,

Cisco Systems, Inc.

CCIE#8933

-=-=-=-