cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
615
Views
5
Helpful
2
Replies

Crypto ISAKMP Policy?

David Draper
Level 1
Level 1

Here is a newbie question. I have a remote 5520 ASA that is configured with a l2l tunnel. The remote ASA has two Crypto ISAKMP policies. How can I tell which policy the ASA is using for the l2l tunnel? The main ASA also has both policies. I just want to clean up the policy that is not being used. Thanks for any help!

Dave

2 Replies 2

ajay chauhan
Level 7
Level 7

The process is something like this-

during phase 1 the initiator sends all of their configured isakmp policies to the peer.The responder then compares its number one policy to all of the policies sent by the peer, stopping as soon as there is a match.If there is no match, then the responder compares its number two policy to all of the policies sent by the peer, stopping as soon as there is a match.This process repeats until a match is found, if no match is found then no SA forms.

You can have multiple policies configured just see both end are configured for same policy .The extra one you can delete.

Thanks

Ajay

Ajay,

     Thanks for the info.  That is what I am looking for. 

     Dave

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: