cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
240
Views
5
Helpful
2
Replies
Highlighted
Beginner

running crypto isakmp on cisco 2901

I have tried creating a vpn tunnel with my 2901 and can not get it to recognize the command crypto isakmp,  I have tried IOS

c2900-universalk9-mz.SPA.154-3.M3 and c2900-universalk9_npe-mz.SPA.155-3.M6.bin.  i have also activated the security lic, i think and only have 4 options after i type crypto.   any ideas?

thanks.

1 ACCEPTED SOLUTION

Accepted Solutions
Highlighted
Frequent Contributor

I run the following -

c2900-universalk9-mz.SPA.155-3.M5.bin

This is on a 2921.

AE-SRST-01(config)#crypto ?


call Configure Crypto Call Admission Control
ctcp Configure cTCP encapsulation
dynamic-map Specify a dynamic crypto map template
engine Enter a crypto engine configurable menu
gdoi Configure GKM (Group Key Management, GDOI or G-IKEv2) Policy
gkm Configure GKM (Group Key Management, GDOI or G-IKEv2) Policy
identity Enter a crypto identity list
ikev2 Configure IKEv2 Options
ipsec Configure IPSEC policy
isakmp Configure ISAKMP policy
key Long term key operations
keyring Key ring commands
logging logging messages
map Enter a crypto map
mib Configure Crypto-related MIB Parameters
pki Public Key components
provisioning Secure Device Provisioning
vpn Configure crypto vpn commands
wui Crypto HTTP configuration interfaces
xauth X-Auth parameters

What is the output of the show license 

Also when you do a show ver, what are the licenses shown at the end?

Did you reboot the router after activating the relevant license? (only required if eval license was not activated beforehand) Was this an evaluation license?

You are using crypto command in Global Config mode? You will need to for the isakmp parameters. Only few options are available in user exec mode.

View solution in original post

2 REPLIES 2
Highlighted
Frequent Contributor

I run the following -

c2900-universalk9-mz.SPA.155-3.M5.bin

This is on a 2921.

AE-SRST-01(config)#crypto ?


call Configure Crypto Call Admission Control
ctcp Configure cTCP encapsulation
dynamic-map Specify a dynamic crypto map template
engine Enter a crypto engine configurable menu
gdoi Configure GKM (Group Key Management, GDOI or G-IKEv2) Policy
gkm Configure GKM (Group Key Management, GDOI or G-IKEv2) Policy
identity Enter a crypto identity list
ikev2 Configure IKEv2 Options
ipsec Configure IPSEC policy
isakmp Configure ISAKMP policy
key Long term key operations
keyring Key ring commands
logging logging messages
map Enter a crypto map
mib Configure Crypto-related MIB Parameters
pki Public Key components
provisioning Secure Device Provisioning
vpn Configure crypto vpn commands
wui Crypto HTTP configuration interfaces
xauth X-Auth parameters

What is the output of the show license 

Also when you do a show ver, what are the licenses shown at the end?

Did you reboot the router after activating the relevant license? (only required if eval license was not activated beforehand) Was this an evaluation license?

You are using crypto command in Global Config mode? You will need to for the isakmp parameters. Only few options are available in user exec mode.

View solution in original post

Highlighted
Beginner

thanks

5