Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Community Member

IKE Phase 1 main and aggressive mode?

Is there a way to specify what mode IKE phase 1 uses? I setup a remote access VPN and while sniffing packets noticed ISAKMP was using Aggressive mode versus Main mode. Is this because it is a remote access VPN connection? Is Main mode only used by the PIX for site-to-site connections?

Thanks in advance

6 REPLIES
Cisco Employee

Re: IKE Phase 1 main and aggressive mode?

If you're referring to the VPN Client, it only uses Aggressive mode, no way to change it.

Silver

Re: IKE Phase 1 main and aggressive mode?

What's the difference between main mode and agressive mode?

Community Member

Re: IKE Phase 1 main and aggressive mode?

Hi,

Main mode uses three two-way exchanges betweeen initiator and receiver.

First - algorithms and hashed used to secure IKE comms are negotiated

Second - Diffe-Hellman exchange to generate shared secret keys and pass nonces to the other peer. These are signed and returned to prove their identity. Shared secret then used to generate all other encryption and authentication keys

Third - Verifies other peers ID to authenticate remote peer.

Aggressive mode:

Fewer exchanges with fewer packets. In first exchange almost everything is squeezed in. IKE negotiation, DH key generation, nonce, ID packet. The receiver sends back everything that's needed to complete the exchange then the initiator confirms the exchange.

Ali

Community Member

Re: IKE Phase 1 main and aggressive mode?

Basically Main mode hide the identities of the peers from prying eyes. Agressive mode exposes the peers identities and sets up the management connection more quickly. Also Main mode has 3 two-way exchanges of six packets and Aggressive mode uses only 2 exchanges. Page 467-468 Cisco PIX Firewalls.

thanks

Community Member

Re: IKE Phase 1 main and aggressive mode?

Just to confirm;

When using the PIX for remote access (vpn client) the PIX only uses aggressive mode. Then main mode is only used in Site-to-Site connections.

Thanks

Silver

Re: IKE Phase 1 main and aggressive mode?

What about when the Pix is creating a "site-to-site" VPN in NEM using the [vpnclient] command set? Does the Pix use aggressive mode like a Unity client would?

3160
Views
0
Helpful
6
Replies
CreatePlease to create content