03-06-2003 12:24 PM - edited 03-09-2019 02:24 AM
Is there a way to specify what mode IKE phase 1 uses? I setup a remote access VPN and while sniffing packets noticed ISAKMP was using Aggressive mode versus Main mode. Is this because it is a remote access VPN connection? Is Main mode only used by the PIX for site-to-site connections?
Thanks in advance
03-06-2003 09:32 PM
If you're referring to the VPN Client, it only uses Aggressive mode, no way to change it.
03-06-2003 10:24 PM
What's the difference between main mode and agressive mode?
03-07-2003 02:57 AM
Hi,
Main mode uses three two-way exchanges betweeen initiator and receiver.
First - algorithms and hashed used to secure IKE comms are negotiated
Second - Diffe-Hellman exchange to generate shared secret keys and pass nonces to the other peer. These are signed and returned to prove their identity. Shared secret then used to generate all other encryption and authentication keys
Third - Verifies other peers ID to authenticate remote peer.
Aggressive mode:
Fewer exchanges with fewer packets. In first exchange almost everything is squeezed in. IKE negotiation, DH key generation, nonce, ID packet. The receiver sends back everything that's needed to complete the exchange then the initiator confirms the exchange.
Ali
03-07-2003 06:03 AM
Basically Main mode hide the identities of the peers from prying eyes. Agressive mode exposes the peers identities and sets up the management connection more quickly. Also Main mode has 3 two-way exchanges of six packets and Aggressive mode uses only 2 exchanges. Page 467-468 Cisco PIX Firewalls.
thanks
03-07-2003 06:06 AM
Just to confirm;
When using the PIX for remote access (vpn client) the PIX only uses aggressive mode. Then main mode is only used in Site-to-Site connections.
Thanks
03-14-2003 01:31 PM
What about when the Pix is creating a "site-to-site" VPN in NEM using the [vpnclient] command set? Does the Pix use aggressive mode like a Unity client would?
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: