cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1708
Views
0
Helpful
2
Replies

ikev1 Transform set issue

av
Level 1
Level 1

Hi

Anyone who can explain to me while below section 1 fails whereas section 2 goes through without any issues? The error I get is: (ERROR) Sent (Wed Oct 24 12:18:45 CEST 2018): crypto ipsec ikev1 transform-set aes_sha2 esp-aes-256 esp-sha256-hmac Received (Wed Oct 24 12:18:46 CEST 2018): crypto ipsec ikev1 transform-set aes_sha2 esp-aes-256 esp-sha256-hmac
^
ERROR: % Invalid input detected at '^' marker. 

Cisco ASA 5516x

 

Failing:

crypto ipsec ikev1 transform-set aes_sha esp-aes-256 esp-sha-hmac
crypto ipsec ikev1 transform-set aes_md5 esp-aes-256 esp-md5-hmac
crypto ipsec ikev1 transform-set aes_sha2 esp-aes-256 esp-sha256-hmac
crypto ipsec ikev1 transform-set 3des_md5 esp-3des esp-md5-hmac
crypto ipsec ikev1 transform-set 3des_sha esp-3des esp-sha-hmac

 

Success:

crypto ipsec ikev1 transform-set aes_sha esp-aes-256 esp-sha-hmac
crypto ipsec ikev1 transform-set aes_md5 esp-aes-256 esp-md5-hmac
crypto ipsec ikev1 transform-set 3des_md5 esp-3des esp-md5-hmac
crypto ipsec ikev1 transform-set 3des_sha esp-3des esp-sha-hmac

1 Accepted Solution

Accepted Solutions

Hi,
SHA2 is not supported when using IKEv1 on the ASA. You'd need to use IKEv2 in order to use the latest/strongest algorithms.

HTH

View solution in original post

2 Replies 2

Hi,
SHA2 is not supported when using IKEv1 on the ASA. You'd need to use IKEv2 in order to use the latest/strongest algorithms.

HTH

That explains it. Thanks.

Review Cisco Networking for a $25 gift card