02-28-2025 07:26 AM
I am having this error message when trying to configure an IPsec-proposal on an ASA for an ikev2 IPSEC tunnel.
ERROR: ipsec policy insertion failed because the maximum proposal limit of 20 was exceeded
ERROR: Unable to insert ipsec-proposal TEST_PROPOSAL
I have been searching online through Cisco's publications, but nothing mentions a limit on ipsec-proposal.
I even checked if it was license issue on the ASA but L2L IPSec are supposed to be unlimited pending the physical resources on your ASA.
Can anyone help me with definitive answer on the limit of transform-set and ipsec-proposals?
Solved! Go to Solution.
02-28-2025 08:19 AM
@rashidevron from the ASA guides -
IKEv1 and IKEv2 each support a maximum of 20 IKE policies, each with a different set of values. Assign a unique priority to each policy that you create. The lower the priority number, the higher the priority.
I would recommend standardising on the most secure ciphers, rather than having so many different variations.
02-28-2025 08:19 AM
@rashidevron from the ASA guides -
IKEv1 and IKEv2 each support a maximum of 20 IKE policies, each with a different set of values. Assign a unique priority to each policy that you create. The lower the priority number, the higher the priority.
I would recommend standardising on the most secure ciphers, rather than having so many different variations.
02-28-2025 09:37 AM
02-28-2025 09:13 AM
Hello @Rob Ingram ,
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide