07-04-2013 08:35 AM
Has any one had the pleasure of trying to build a VPN tunnel between IOS and ASA using ikev1 and DH group 14?
The ASDM allows me to select grooup 14 but the CLI returns an error when the command is applied.
Solved! Go to Solution.
07-04-2013 11:33 PM
You need to move to IKEv2, there you have support for DH-Group 14 both on IOS and the ASA.
--
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni
07-04-2013 09:00 PM
hi,
was the error on the router IOS? could you post the CLI error?
07-04-2013 11:12 PM
No it was in the asa. The asa woul only take 'group 1.2,5 or 7'
07-04-2013 11:33 PM
You need to move to IKEv2, there you have support for DH-Group 14 both on IOS and the ASA.
--
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni
07-05-2013 01:23 AM
Thats a shame becuase my IOS devices is in production, not sure I'll be able to move to IKEv2
07-05-2013 01:34 AM
Thats a shame becuase my IOS devices is in production, not sure I'll be able to move to IKEv2
Yes, it would be really nice to have that on the ASA. Are you already on DH5 for your VPNs? With that you had at least more security then the avarage VPN-Admin. Most VPNs I see are still running DH2 (and some to my astonishment even with DH1).
--
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: