08-03-2011 02:46 AM
Guys we have Headoffice ASA connected to Branch ASA via site to site VPN tunnel. The headoffice ASA has priority 11,20 and 40 configured, while the branch has only IKE priority 50 defined and no default priority is visible under show run. Based on this information should the VPN tunnel between headoffice and branch establish?
Solved! Go to Solution.
08-03-2011 07:23 AM
Bhushan,
When you speak IKE Policy priorities, you are refferring to crypto isakmp policies right?
If that is the case, the number that you use to identify those is locally significant. It doest matter if you have crypto isakmp policy 1 on one side and crypto isakmp policy 5 on the other side, as long one policy on each site and that the parameters match (encryption, authentication, hash, dh group, preshared key) your Phase 1 should come up.
I hope this helps.
Raga
08-03-2011 07:27 AM
Just to add to to Raga's post. ISAKMP policies are run through in the order they are numbered. So if your remote site onlu has one ISAKMP policy when it connects your HQ ASA will simply test each ISAKMP Policy it has configured against the branch ISAKMP settings until it either finds one or gets to the end and hasn't matched any.
As Raga says, the actual numbers are only locally significant.
Jon
08-03-2011 07:23 AM
Bhushan,
When you speak IKE Policy priorities, you are refferring to crypto isakmp policies right?
If that is the case, the number that you use to identify those is locally significant. It doest matter if you have crypto isakmp policy 1 on one side and crypto isakmp policy 5 on the other side, as long one policy on each site and that the parameters match (encryption, authentication, hash, dh group, preshared key) your Phase 1 should come up.
I hope this helps.
Raga
08-03-2011 07:27 AM
Just to add to to Raga's post. ISAKMP policies are run through in the order they are numbered. So if your remote site onlu has one ISAKMP policy when it connects your HQ ASA will simply test each ISAKMP Policy it has configured against the branch ISAKMP settings until it either finds one or gets to the end and hasn't matched any.
As Raga says, the actual numbers are only locally significant.
Jon
08-04-2011 02:06 AM
Thanks to both Luis and Jon for clarifying my doubts.
Regards
08-04-2011 07:04 AM
Sure anytime
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide