Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Hi,
Cisco confirmed in their doc that Dynamic RRI applies to IKEv2 based static crypto maps only. See link below
https://www.cisco.com/c/en/us/td/docs/security/asa/asa98/configuration/vpn/asa-98-vpn-config/vpn-ike.html
However, when I configured...
Hi Friends,
I have a site-2-site IPsec tunnel (using IKev2 and FlexVPN) between a remote site and a Hub. Everything is working fine including the IKEv2 routing used for the route exchanges. However, after a couple of weeks, the tunnel stops working ...
Hi,
I am keen to finding out how many concurrent tunnel sessions and throughput can be achieved for a DMVPN/IKEv2/IPsec with BGP solution on the following platforms. I am currently working on a design to deploy approximately 3000 remote sites (Spok...
Hi
I am testing IKEv2/IPSEC with HA in the LAB but encountering some issues with respect to failover between the HA clustered IPSEC concentrators and the remote peer.
SA is established between the remote peer and the active concentrator. However, w...
Thanks Karsten for your reply.
I was actually thinking of upgrading to 155-3.M4a if it resolves the issue. I will keep you updated if the issue doesn't re-occur following the upgrade. Thanks.
Hi thiland,
I have tested FlexVPN and it worked as expected. Also, using the IKev2 routing which is more or less static routing and this has the advantage of reducing traffic overheads associated with dynamic protocols. I believe this would improve ...
Thanks Thiland for your reply.
I really don't know much about FlexVPN but if I may ask, with IKEv2 routing/FlexVPN, I believe I will not be needing any dynamic routing, rather using the IKEv2 authorisation to inject/accept routes.
If I am to start wi...
Thanks Pjain2 for your help.
I have only 1 ISP and I am using 2 routers to setup the IPSEC HA which sit behind a clustered checkpoint firewall.
However, the issue has been resolved. I didn't setup DPD on the remote IPSEC router, hence why the SA wa...