Hi Guys, I am currently trying to configure a VPN link between 2 sites, I have replaced some crypto maps with ipsec tunnel interfaces instead. However I am unsure what configuration lines are still required below is snippets of the configuration, both sites have similar configurations however the documentation I found doesn't show the use of crypto isakmp policy line but when I remove it the link fails to establish.
crypto isakmp policy 3
crypto isakmp key keygoeshere address xxx.xxx.xxx.xxx
crypto ipsec transform-set ESP-3DES-SHA1 esp-3des esp-sha-hmac
crypto ipsec profile Site-to-Site
set transform-set ESP-3DES-SHA1
description --- Connection to WA ---
ip address 192.168.250.1 255.255.255.252
tunnel source Dialer1
tunnel destination xxx.xxx.xxx.xxx
tunnel mode ipsec ipv4
tunnel protection ipsec profile Site-to-Site
If you plan to use IPsec as the VPN protocol, you cannot remove the crypto isakmp policy (because it is used for phase 1 negotiation between the VPN endpoints).
You're using IPsec profiles, is this because you're establishing VTI or GRE VPN tunnels?
What kind of VPN are you trying to establish?