09-07-2020 07:34 AM
Hi All
With IKE V2
I believe it still has a phase and phase 2 proposal (init and auth)
On the ASA, is the ike policy the phase 1 and the ipsec proposal phase 2 for ike v2?
cheers
09-07-2020 07:41 AM - edited 09-07-2020 09:51 AM
Hi,
Yes. The IKEv2 policy is used to establish the IKEv2 SA (INIT/Phase 1) and the IPSec Proposal (Transform Set) is used to establish the IPSec SA (AUTH/Phase 2).
HTH
09-08-2020 05:17 PM
yes, that's right. For stability aand security reasons, prefer IKEv2 hiwhc is supported across all vendors as today.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: