cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
20236
Views
10
Helpful
6
Replies

Cisco Router with IKEV2 support

dilshannet
Level 1
Level 1

Hi, Does anyone know a router ios for c3600, c7200, c2600 that support ikev2? (command crypto ikev2 )

6 Replies 6

IKEv2 was first supported in IOS 15.1.1T with site-to-site. As this version is not available on the older 2600 and 3600 routers, they can't be configured with IKEv2.


Sent from Cisco Technical Support iPad App

Thanks karsten. Do u have the IKEv2 configuration (command line) for IOS router. Following are the  phase 1 and phase 2 requirements.

Phase 1

Authentication method          : preshared

Encryption Algorithm            : AES-256

Hash                                   : MD5

DH                                      : Group 2

Lifetime                               : 1440 minutes

Mode                                  : Main mode

Phase 2

Encapsulation                    :     ESP

Encryption Algorithm          :     3DES

Hash                                 :     SHA-1

PFS                                  :     No PFS

Lifetime                             :     3600 seconds

here is a guide with all needed configuration:

http://www.cisco.com/en/US/docs/ios-xml/ios/sec_conn_ikevpn/configuration/15-1mt/Configuring_Internet_Key_Exchange_Version_2.html

-- 
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni

olpeleri
Cisco Employee
Cisco Employee

Hello Tharaka,

It's not available on ISR G1.

ikev2 is available on ISR G2 [ 1900 - 2900 - 3900 - 880's 890's ] onwards [ and ASR1000].

Cheers,

thanks

veneet.thakur
Level 1
Level 1

 Is there any impact of enabling IKEv2 to existing IPSec tunnels configured with IKEv1.

rgds,