10-11-2001 04:14 AM - edited 02-21-2020 09:57 AM
i am doing a site-to-site vpn experiment with two router.one is 3660(Ra).another is provided by other(Rb).if Ra initiates the negotiation, a new isakmp sa can be got but authentication fails.otherwise Rb is the initiator, the isakmp sa negotiation can be finished normally.i migrated the configurations of Rb to a 3640 router unchanged.the negotiation of the phase 1 exchange is finished normally without regard to the direction.Rb's provider assured their products were compatible with RFC2409 strictly.does Cisco have some private policies in the authentication during the phase 1 negotiation?
any help would be appreciated
10-16-2001 12:40 PM
Check your IOS. Sounds like a bug to me. Anyone else run into this?
11-29-2001 09:09 PM
i work it out, is it a bug, or a proprietary policy?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide