01-11-2012 07:37 AM
Here is a newbie question. I have a remote 5520 ASA that is configured with a l2l tunnel. The remote ASA has two Crypto ISAKMP policies. How can I tell which policy the ASA is using for the l2l tunnel? The main ASA also has both policies. I just want to clean up the policy that is not being used. Thanks for any help!
Dave
01-11-2012 09:09 AM
The process is something like this-
during phase 1 the initiator sends all of their configured isakmp policies to the peer.The responder then compares its number one policy to all of the policies sent by the peer, stopping as soon as there is a match.If there is no match, then the responder compares its number two policy to all of the policies sent by the peer, stopping as soon as there is a match.This process repeats until a match is found, if no match is found then no SA forms.
You can have multiple policies configured just see both end are configured for same policy .The extra one you can delete.
Thanks
Ajay
01-11-2012 09:18 AM
Ajay,
Thanks for the info. That is what I am looking for.
Dave
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: