The branch not working is using paremeters used in policy 2 . How can ensure that specific branch is using policy 2 ? The below is the debug for my VPN Tunnel .
Each VPN endpoint innitiating the connection will send all of his isakmp's policies until a match happens, so if branch two also has isakmp policie one, that would be a match and they will use that one. as the first match is the one used.
Do rate all the helpful posts
Julio Carvajal Senior Network Security and Core Specialist CCIE #42930, 2xCCNP, JNCIP-SEC
It's not a phase 1 issue. Notify message 14 "NO_PROPOSAL_CHOSEN" can be used in both phase 1 and phase 2. In this case you can see that phase 1 has completed and the notify message was received during quick mode. I would first check the the phase 2 transform set and then the proxy ID (subnet) info as the INVALID_ID_INFO notify message isn't always used for host/subnet incompaibilities.
BenefitsDocumentationPrerequisiteImage Download LinksLimitationsSupported PlatformsLicense RequirementsTopologyStep-By-Step ConfigurationConfigure Virtual ServiceActivate the virtual service and configure guest IPsConfiguring UTD (Service Plane)Configurin...
Login to the FXOS chassis manager.
Direct your browser to https://hostname/, and log-in using the user-name and password.
Go to Help > About and check the current version:
Check the current version availa...
We have configured the outside and inside Interface with official ipv6 adresses, set a default route on outside Interface to our router, we also have definied a rule , which also gets hits, to permit tcp from inside Interface to any6.
In Syslog I also se...