cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
325
Views
0
Helpful
2
Replies

VPN concentrator to VPNSM

m.saunders
Level 1
Level 1

Hi, I have a couple of remote clients using a Cisco VPN concentrator who connect to our VPNSM through an IPSEC encrypted tunnel. On my end, I configure my transform-set to MD5 but it seems that on the remote end they have to configure Phase 2 to SHA in order to get the tunnel to work. I would have assumed that the tunnel wouldn't have even come up if both ends didn't match for the encryption piece?? Anyone else have a similar situation and can explain to me why this would even work? thanks

2 Replies 2

irisrios
Level 6
Level 6

Security parameters have to be same on both the ends. Only then the tunnel would come up. I still haven't seen a working configuration with mismatch in security parameters.

Thanks for the reply and that's what I thought too. Doesn't make any sense to me.