cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1546
Views
0
Helpful
1
Replies

SHA2 on ASA for Phase 2

Hi,

I am looking into configuring SHA2 for message integrity in phase 2 IPSEC on our ASA5510.

Under the ipsec-proposal setting you only have the option for SHA1:

crypto ipsec ikev2 ipsec-proposal AES256
protocol esp encryption aes-256
protocol esp integrity sha-1

We are running software version 9.1(7)

Am I missing something here?

1 Reply 1

Philip D'Ath
VIP Alumni
VIP Alumni

Can't be done on a 5510.  You'll need to upgrade to something current like a 5516.