cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3542
Views
0
Helpful
6
Replies

IKE Phase 1 main and aggressive mode?

adisegna
Level 1
Level 1

Is there a way to specify what mode IKE phase 1 uses? I setup a remote access VPN and while sniffing packets noticed ISAKMP was using Aggressive mode versus Main mode. Is this because it is a remote access VPN connection? Is Main mode only used by the PIX for site-to-site connections?

Thanks in advance

6 Replies 6

gfullage
Cisco Employee
Cisco Employee

If you're referring to the VPN Client, it only uses Aggressive mode, no way to change it.

What's the difference between main mode and agressive mode?

Hi,

Main mode uses three two-way exchanges betweeen initiator and receiver.

First - algorithms and hashed used to secure IKE comms are negotiated

Second - Diffe-Hellman exchange to generate shared secret keys and pass nonces to the other peer. These are signed and returned to prove their identity. Shared secret then used to generate all other encryption and authentication keys

Third - Verifies other peers ID to authenticate remote peer.

Aggressive mode:

Fewer exchanges with fewer packets. In first exchange almost everything is squeezed in. IKE negotiation, DH key generation, nonce, ID packet. The receiver sends back everything that's needed to complete the exchange then the initiator confirms the exchange.

Ali

Basically Main mode hide the identities of the peers from prying eyes. Agressive mode exposes the peers identities and sets up the management connection more quickly. Also Main mode has 3 two-way exchanges of six packets and Aggressive mode uses only 2 exchanges. Page 467-468 Cisco PIX Firewalls.

thanks

Just to confirm;

When using the PIX for remote access (vpn client) the PIX only uses aggressive mode. Then main mode is only used in Site-to-Site connections.

Thanks

What about when the Pix is creating a "site-to-site" VPN in NEM using the [vpnclient] command set? Does the Pix use aggressive mode like a Unity client would?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: