01-30-2011 08:10 PM
What's the IKE negotiation mode used in a a dynamic VPN tunnel group, i.e. DefaultL2LGroup? Main, Aggresive or Auto-negotiate? Thanks!
Solved! Go to Solution.
01-30-2011 11:00 PM
ok.
I guess you are looking for the following command.
crypto map [TAG] [SEQ#] set phase1-mode aggressive
Regards,
Anisha
P.S.: Please mark this thread resolved if your query is resolved.
01-30-2011 09:46 PM
Hi,
I did not understand your meaning of dynamic VPN tunnel? Do mean the RA VPN tunnel-group i.e. Dynamic map?
For a VPN Tunnel trying to negotiate on dynamic crypto map, aggressive mode is first negotiated then main mode.
Regards,
Anisha
P.S.: Please mark this thread as resolved if you feel your query is answered.
01-30-2011 09:56 PM
Thanks a lot. It seems that there is no way to set the negotiation mode for a dynamic map in ASA. Is it correct?
01-30-2011 10:07 PM
Hi,
You can disable the Aggressive mode.
Disabling aggressive mode prevents Cisco VPN clients from using preshared key authentication to establish tunnels to the security appliance. However, they may use certificate-based authentication (that is, ASA or RSA) to establish tunnels.
The following link gives you details of the same.
http://www.cisco.com/en/US/docs/security/asa/asa70/configuration/guide/ike.html#wp1051341
Regards,
Anisha
P.S.: please mark this thread as resolved if you feel your query is answered.
01-30-2011 10:12 PM
I'm referring to dynamic L2L tunnel. Do you have any info for the IKE negotation mode for this type of tunnel?
01-30-2011 10:24 PM
What do you mean by dynamic L2L tunnel?
Are you refering to EZVPN tunnel?
Regards,
Anisha
01-30-2011 10:38 PM
Ok, put it in a Cisco ASA context, it is the DefaultL2LGroup.
01-30-2011 10:44 PM
Hi,
I am still lost with your requirement.
if the ASA is in multiple context mode then one cannot terminate VPN on it.
http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/contexts.html#wp1146698
Regards,
Anisha
01-30-2011 10:49 PM
I'm sorry to make you feel lost. Put it simple. is there any way to fix the negotiation mode in a dynamic map, i.e. either aggressive or main. Through your previous explanation, i know the remote peer/client will try aggressive first, then main, but I want it to be a fixed mode. Thanks!
01-30-2011 11:00 PM
ok.
I guess you are looking for the following command.
crypto map [TAG] [SEQ#] set phase1-mode aggressive
Regards,
Anisha
P.S.: Please mark this thread resolved if your query is resolved.
01-30-2011 11:02 PM
Is it possible to set it via ASDM? Thanks!
01-30-2011 11:23 PM
I am not a ASDM person, am a CLI person.
I guess you can put the one command via CLI.
Regards,
Anisha
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide