08-28-2017 07:10 AM - edited 03-12-2019 04:30 AM
I have received ipsec parameters for phase 1/2 from a non-ASA customer:
Phase 1
authentication-method | pre-shared-keys |
authentication-algorithm | sha-256 (384) |
encryption-algorithm | aes-192-cbc (256) |
dh-group | group2 |
lifetime-seconds | 28800 |
Phase 2
authentication-algorithm | sha-256 |
encryption-algorithm | aes-192-cbc (256) |
protocol | esp |
lifetime-seconds | 3600 |
perfect-forward-secrecy keys | none |
Can you help with creating corresponding transform-set and crypto policy?
Thanks!
Solved! Go to Solution.
08-31-2017 06:44 AM
08-30-2017 10:21 AM
Hello @captkloss,
Before any suggestion is made, can you specify if this VPN tunnel is IKEv1 or IKEv2?.
Have a good one!
Gio
08-30-2017 10:35 AM
Hello,
The other party claims they use ikev1 - however i cant see an option to match sha256 using ikev1.... so i'm bit confused...
08-31-2017 06:44 AM
08-30-2017 10:23 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide