cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2250
Views
0
Helpful
1
Replies

when main mode and aggressive mode is used?

seshuchkv
Level 1
Level 1

when main mode and aggressive mode is used?

1 Reply 1

Dinesh Moudgil
Cisco Employee
Cisco Employee

Main mode:-
An IKE session begins with the initiator sending a proposal or proposals to the responder. The proposals define what encryption and authentication protocols are acceptable, how long keys should remain active, and whether perfect forward secrecy should be enforced, for example. Multiple proposals can be sent in one offering. The first exchange between nodes establishes the basic security policy; the initiator proposes the encryption and authentication algorithms it is willing to use. The responder chooses the appropriate proposal (we'll assume a proposal is chosen) and sends it to the initiator. The next exchange passes Diffie-Hellman public keys and other data. All further negotiation is encrypted within the IKE SA. The third exchange authenticates the ISAKMP session. Once the IKE SA is established, IPSec negotiation (Quick Mode) begins.

Aggressive mode:-
Aggressive Mode squeezes the IKE SA negotiation into three packets, with all data required for the SA passed by the initiator. The responder sends the proposal, key material and ID, and authenticates the session in the next packet. The initiator replies by authenticating the session. Negotiation is quicker, and the initiator and responder ID pass in the clear.


In essence, 

* L2L VPN with pre shared key uses Main mode. It can also be configured for Aggressive mode.
* L2L VPN with certificates uses Main mode.

* Remote access vpn with pre shared key uses Aggressive mode. 
* Remote access vpn with certificate uses Main mode. 


Here is document for your reference:-
https://supportforums.cisco.com/document/31741/main-mode-vs-aggressive-mode


Regards,
Dinesh Moudgil

P.S. Please rate helpful post.

Cisco Network Security Channel - https://www.youtube.com/c/CiscoNetSec/