cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
314
Views
0
Helpful
2
Replies

Dial backup VPN - preshare key issue

agos-hicl
Level 1
Level 1

I'm using dial backups to my DSL connections in case of failure but on my host router I also use EZVPN Server for Client VPN access. As a result the the EZVPN Server uses xauth for preshare authentication:

crypto isakmp key ??????? address 0.0.0.0 0.0.0.0

BUT for my dial backup VPN to work I need to use dynamic IP for the peer IP address thus requiring:

crypto isakmp key ?????? address 0.0.0.0 0.0.0.0 no xauth

I've tried configuring keys for the dial-in subnets, but it still seems to use the default.

Is this simply not supported or is there a workaround?

My host (main) router is a CISCO 1841, my remote router is 877.

Cheers,

Sean

1 Accepted Solution

Accepted Solutions

kaachary
Cisco Employee
Cisco Employee

You need to configure ISAKMP profiles on the Ezvpn server router.

http://cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a00801dddbb.shtml

That would do it.

View solution in original post

2 Replies 2

ivillegas
Level 6
Level 6

As far as I know it is supported. Have a look at the following URL for configuration http://cisco.com/en/US/products/ps6635/products_white_paper0900aecd80393720.shtml

kaachary
Cisco Employee
Cisco Employee

You need to configure ISAKMP profiles on the Ezvpn server router.

http://cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a00801dddbb.shtml

That would do it.