cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2048
Views
0
Helpful
2
Replies

VPN IKV2 does not works PHASE 1

HaroldCalderon
Level 1
Level 1

Hello  everybody 

 

I made a VPN ikv2 but does not up phase 1, I think a Conver all but no work.

 

I was talking to my networking friends and the only different in them configuration and mine its  this

 

My Config

 

group-policy DfltGrpPolicy attributes
vpn-tunnel-protocol ikev1 l2tp-ipsec ssl-clientless    ( no ikev2 )

 

configuration of my networking friends

 

group-policy DfltGrpPolicy attributes

vpn-tunnel-protocol ikev1 ikev2  ( yes ikv2) 

 

someone has something like this, please your help

 

 

----------------------------------------------------------------------------------

 

A let my configuration

 

crypto ipsec ikev2 ipsec-proposal ABCD

 protocol esp encryption aes-256

 protocol esp integrity sha-384

 

crypto ikev2 policy 50

 encryption aes-256

 integrity sha

 group 19

 prf sha384

 lifetime seconds 28800

 

crypto map VPN-SITE-TO-SITE 15 match address ABCD_acl

crypto map VPN-SITE-TO-SITE 15 set pfs group19

crypto map VPN-SITE-TO-SITE 15 set peerX.X.X.X

crypto map VPN-SITE-TO-SITE 15 set ikev2 ipsec-proposal ABCD

crypto map VPN-SITE-TO-SITE 15 set security-association lifetime seconds 3600

 

crypto ikev2 enable OUTSIDE

 

tunnel-group ABCD type ipsec-l2l

tunnel-group ABCD ipsec-attributes

 ikev2 remote-authentication pre-shared-key *****

 ikev2 local-authentication pre-shared-key *****

 

group-policy DfltGrpPolicy attributes
vpn-tunnel-protocol ikev1 l2tp-ipsec ssl-clientless

 

 

2 Replies 2

Hi,

Yes, you need to define IKEv2 under the group-policy DfltGrpPolicy as your networking friends have.

 

 

 

thaks I gonna try and let you know how was

 

 

Review Cisco Networking products for a $25 gift card