08-16-2018 01:16 AM
Hello
Is there a way to give each tunnel its own IKE policy?
My problem is that I have created several, because we have many VPN partners.
If I now want to select the IKE policy for the Conection Profiles in the ASDM, I always get the message "IKE police global.It is shared by all IPsec connection profile". It happens again and again that the other side has different attitudes than at the end the ASA takes. This always leads to problems with the VPN tunnel. I would like to assign exactly one policy to the tunnels.
Does anyone know how this works? This is also possible with other renowned manufacturers.
Many Thanks
08-16-2018 02:37 AM
08-16-2018 04:03 AM
The ASA already gives you the answer: All peers share the same sets of policies. And as long as the other side has a matching policy it should work. The only problem is that the ASA could negotiate a weaker policy that doesn't match your security-policy.
Two possible workarounds for that problem:
08-16-2018 04:46 AM
Both solutions are not possible.
On the one hand, both sides must be able to build up the tunnel.
on the other hand, we often have different lifetime to different VPN partners. Here is often also the biggest problem that the ASA thinks a policy with other lift time takes even though the counterpart has set a completely different.
Is there no other possibility? For VPN Gateway from other manufacturers, I know that you can do everything per tunnel according to the settings.
08-16-2018 05:06 AM
Lifetimes are used as the smallest value of the matching policies in IKEv1. They don't have to be the same on both ends. And there shouldn't arise a problem of that; at least not a technical one.
I do not think that you can accomplish this with the ASA.
08-16-2018 05:10 AM
Unfortunately, we have often had technical problems with VPN Traffic due to different Lifetime
08-16-2018 05:29 PM
08-17-2018 12:20 AM
Really? When setting up VPNs to third-parties, I never care about the different lifetime and never had problems that were related to these. Very strange ...
08-16-2018 04:02 PM
08-16-2018 11:13 PM
How would the procedure be with IKVv2?
There are global attitudes as well
08-17-2018 02:18 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide