Resolution
Phase 1 must be encrypted, but phase 2 may be configured without encryption.
- VPN 3000 Concentrator
- Navigate to Configuration > Policy Management > Traffic Management > SAs.
- Click Add to add a new security association (SA).
- For the encryption algorithm, select null and configure the remaining settings for this SA.
- Apply the new SA to your group.
- Cisco IOS router or PIX Firewall
Add the following command to your configuration.
crypto ipsec transform-set nullset esp-null esp-md5-hmac