IKE Phase 2 negotiated options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-01-2006 11:31 AM
Hi,
I just wanted some clarification on a point if someone would be kind enough to help.
During IKE Phase 2 exchange, my understanding is that the transform sets are agreed on, in order to establish the IPSEC SA.
Can someone confirm whether the "Interesting Traffic" pattern/acl is exchanged between the peers with the expectation on a mirrored match? My understanding is that it isn't, but this is being challenged by a fairly knowledgable chap I know.
If someone could confirm my understanding is correct (or the reverse) and let me know if there are any other options exchanged at Phase 2 I'd be really grateful.
Regards,
Paul
- Labels:
-
VPN
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-01-2006 02:34 PM
totally agree.
i don't think phase 2 will go through examiningg the acl. in fact, i don't think the acl is going to examine at all.
i have setup lan-lan vpn between 10+ remote offices with 837, and pix515e at the head office. all 837s have crypto acl like:
permit ip
whereas with the pix,
permit ip host
