cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
939
Views
0
Helpful
1
Replies

Configuring main mode in VPN site to site

abdielmoyano
Level 1
Level 1

Hello guys,

 

A client is asking me to implement a vpn site to site using main mode. But I have a Cisco ASA 5525 version 9.1(1) with its default value aggressive mode. I think that If I use the command "crypto ikev1 am-disable" in the global configuration mode I will affect my others vpn connections (in aggressive mode), so, is there a way to make it affecting just one VPN configuration?

 

Regards!

1 Reply 1

Hi,
You can determine whether your existing tunnels are using aggressive mode by checking the output of "show crypto isakmp sa" check to confirm whether the state is QM or MM. If all existing tunnels are using Main Mode, you should just be able to disable aggressive mode globally - this should not impact existing tunnels, however implement the change during a change window.

HTH
Review Cisco Networking for a $25 gift card