cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
513
Views
0
Helpful
4
Replies

EzVPN using AES_256

gtickle
Level 1
Level 1

I can not get ezvpn to worl with aes 256 it works with 3des and aes 128. Has any been able to to get ezvpn to work with AES 256?

4 Replies 4

vkapoor5
Level 5
Level 5

check if your image supports AES encryption.

asp13
Level 1
Level 1

Which device do you use?

I have the same situation. My ezVPN server is VPN Concentrator and ezVPN Remote - IOS 12.4.

I suppose the problem is in IOS because 'sh crypto ipsec sa' shows there is no aes-256 or eas-192 transform sets.

I've open the case but still got no response form TAC.

Cisco 2821 as EzVPN server 2801 as remote. I tried 12.4 and 12.3(14) I cound not get it to work with AES 256 but it will work with AES 128. I just switched everything to DMVPN it works great.

Yes, as i said hardcoded transform sets in IOS ezVPN Remote code doesn't have an aes-256 proposal. So when you switched to DMVPN you made statical transform set.

I've got a response from TAC which state that it's a "design decision". A bit silly decision to my mind, it looks like a trivial bug.

Lets hope this we'll be corrected in future releases of IOS.