06-17-2016 06:59 AM
Hello Everyone,
I have query related to IKEv1 to IKEv2 feasibility.
Currently I am using ASA5540 with Software Version 9.1(6)11.
On this ASA we are using IKEv1 and having almost 240 Active SA/tunnels.
Now I have received request to change IKEv1 to IKEv2 only for TWO tunnels and keep other on IKEv1 as it is.
Here my question are;
Active SA: 240
Total IKE SA: 240
I am not that expert in this. Could you pls guide & advise me.
Your help would be greatly appreciated.
Best regards,
Nishikesh Deshmukh
Solved! Go to Solution.
06-17-2016 07:29 AM
You can run both IKEv1 and IKEv2 at the same time. With enabling IKEv2 on the outside interface, nothing will actually happen with your tunnels. Only if the other side is also configured for IKEv2 and your ASA has all needed config in place, the configured VPNs will change to IKEv2.
What you need to do:
06-17-2016 07:29 AM
You can run both IKEv1 and IKEv2 at the same time. With enabling IKEv2 on the outside interface, nothing will actually happen with your tunnels. Only if the other side is also configured for IKEv2 and your ASA has all needed config in place, the configured VPNs will change to IKEv2.
What you need to do:
06-17-2016 10:32 AM
Hello Karsten,
Thanks for the information.
Yes, we are configuring IKEv2 on both sides.
Actually I was worried about other existing/production tunnels.
Thanks for your help.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide