cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
312
Views
0
Helpful
2
Replies

Dial backup VPN - preshare key issue

agos-hicl
Level 1
Level 1

I'm using dial backups to my DSL connections in case of failure but on my host router I also use EZVPN Server for Client VPN access. As a result the the EZVPN Server uses xauth for preshare authentication:

crypto isakmp key ??????? address 0.0.0.0 0.0.0.0

BUT for my dial backup VPN to work I need to use dynamic IP for the peer IP address thus requiring:

crypto isakmp key ?????? address 0.0.0.0 0.0.0.0 no xauth

I've tried configuring keys for the dial-in subnets, but it still seems to use the default.

Is this simply not supported or is there a workaround?

My host (main) router is a CISCO 1841, my remote router is 877.

Cheers,

Sean

1 Accepted Solution

Accepted Solutions

kaachary
Cisco Employee
Cisco Employee

You need to configure ISAKMP profiles on the Ezvpn server router.

http://cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a00801dddbb.shtml

That would do it.

View solution in original post

2 Replies 2

ivillegas
Level 6
Level 6

As far as I know it is supported. Have a look at the following URL for configuration http://cisco.com/en/US/products/ps6635/products_white_paper0900aecd80393720.shtml

kaachary
Cisco Employee
Cisco Employee

You need to configure ISAKMP profiles on the Ezvpn server router.

http://cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a00801dddbb.shtml

That would do it.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: