06-21-2020 08:30 PM
Hello,
I see the following output in our asa having an ipsec vpn to one of our vendors. please help me understanding the below.
a) What does esp-aes-256 & esp-sha-hmac both mean in transfor, both these entries are different so why is it showing both?
b) what does IKEv1 indicate?
inbound esp sas:
spi: 0x21342104 (557060440)
transform: esp-aes-256 esp-sha-hmac no compression
in use settings ={L2L, Tunnel, IKEv1, }
slot: 0, conn_id: 212406151, crypto-map: verti_vend
sa timing: remaining key lifetime (kB/sec): (4371273/8464)
IV size: 16 bytes
replay detection support: Y
Anti replay bitmap:
0xFFFFFFFF 0xFFFFFFFF
outbound esp sas:
spi: 0x957DB7F1 (2504380561)
transform: esp-aes-256 esp-sha-hmac no compression
in use settings ={L2L, Tunnel, IKEv1, }
slot: 0, conn_id: 212406151, crypto-map: verti_vend
sa timing: remaining key lifetime (kB/sec): (4365423/8428)
IV size: 16 bytes
replay detection support: Y
Anti replay bitmap:
0x00000000 0x00000001
Solved! Go to Solution.
06-21-2020 11:05 PM
06-21-2020 11:05 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide