cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1479
Views
0
Helpful
1
Replies

how to remove the default isakmp policy on a ciso router (3845)

west33637
Level 1
Level 1

hello all. My company recently failed a PCI scan because our router was returning 56bit des encryption for isakmp negotiation on an existing default isakmp policy. How do I remove this default isakmp policy. I am not running 12.4(15)T1 so the no crypto isakmp policy default does not work. Is there any way other than upgrading the IOS? Any suggestions?

Is there any way to configure a maximum number of isakmp policies that an authenticating router will check? I have 2 configured higher priority ISAKMP policies. Maybe if there is a command to limit the number of isakmp policies the router checks, that would eliminate this default policy being matched?

Thanks.

1 Accepted Solution

Accepted Solutions

Jennifer Halim
Cisco Employee
Cisco Employee

Turning off the default isakmp policy is only supported from IOS version 12.4(20)T onwards. Earlier version does not support turning off the default

isakmp policy.

Here is the command for your reference on when it is first released:

http://www.cisco.com/en/US/docs/ios/security/command/reference/sec_c4.html#wp1051491

View solution in original post

1 Reply 1

Jennifer Halim
Cisco Employee
Cisco Employee

Turning off the default isakmp policy is only supported from IOS version 12.4(20)T onwards. Earlier version does not support turning off the default

isakmp policy.

Here is the command for your reference on when it is first released:

http://www.cisco.com/en/US/docs/ios/security/command/reference/sec_c4.html#wp1051491