cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1298
Views
20
Helpful
3
Replies

SHA-2 supported in IPSEC IKEv2

camty81
Level 1
Level 1

Hi,

 

I have ASA 5545-x with firmware 8.6(1), wanted to know, does it support SHA-2 in IPsec IKEv2?

 

Thanks

Cam

1 Accepted Solution

Accepted Solutions

Hi @camty81 

ASA 8.6 supports IKEv2 but doesn't appear to support SHA-2, only SHA and MD5 as validate integrity methods.


Reference

https://www.cisco.com/c/en/us/td/docs/security/asa/asa84/configuration/guide/asa_84_cli_config/vpn_site2site.html#wp1042828

 

I'd suggest upgrading your ASA, your hardware supports up to version 9.14

Upgrade path:-

https://www.cisco.com/c/en/us/td/docs/security/asa/upgrade/asa-upgrade/planning.html#ID-2152-0000000a

View solution in original post

3 Replies 3

Hi @camty81 

ASA 8.6 supports IKEv2 but doesn't appear to support SHA-2, only SHA and MD5 as validate integrity methods.


Reference

https://www.cisco.com/c/en/us/td/docs/security/asa/asa84/configuration/guide/asa_84_cli_config/vpn_site2site.html#wp1042828

 

I'd suggest upgrading your ASA, your hardware supports up to version 9.14

Upgrade path:-

https://www.cisco.com/c/en/us/td/docs/security/asa/upgrade/asa-upgrade/planning.html#ID-2152-0000000a

Hi @Rob Ingram 

 

Thank you for the feedback and suggestion.

upgrade to 9.8.4 we recentely upgrade to 9.14 had issue and TAC recommand to use 9.8.4 as it a gold star release.

please do not forget to rate.