cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1893
Views
0
Helpful
1
Replies

IPSec Phase 1 & Phase 2: differences in commands

azhdar1234
Beginner
Beginner

Hello !

What's difference between "hash sha / encryption aes256" in Phase 1 and "esp-sha256-hmac" in Phase 2 ? Are they the same or are there any difference ?

1 Reply 1

Hi,
The algorithms defined in Phase 1 (isakmp policy) are used to establish an IKE SA (Security Association), through which 2 x IPSec SA (inbound/outbound) is negotiated using the Phase 2 algorithms defined in the IPSec Transform Set. All data transmitted through the VPN is over the IPSec SAs.

HTH
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: