Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

isakmp enable outside

should we always enable isakmp on outside int for site-site vpn or can we cahnge the int?

1 REPLY
Cisco Employee

Re: isakmp enable outside

Aksher,

IKE is a protocol used by IPSec for completion of Phase 1. IKE negotiates and assigns SAs for each IPSec peer, which provide a secure channel for the negotiation of the IPSec SAs in Phase 2.

If you are terminating IPSEC tunnels on the outside interface, then you need to enable isakmp on the outside. In case if you are terminating IPSEC Tunnels on the DMZ, then you need to enable Isakmp on the DMZ.

Please refer the below URL for details:

http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_62/config/ipsecint.htm#wp1028911

Let me know if it helps.

Regards,

Arul

106
Views
5
Helpful
1
Replies
CreatePlease login to create content