Cisco ASA 5505 Configuration Manual page 1285

Asa 5500 series
Hide thumbs Also See for ASA 5505:
Table of Contents

Advertisement

Chapter 63
Configuring IKE, Load Balancing, and NAC
If you do not configure any IKE policies, the adaptive security appliance uses the default policy, which
is always set to the lowest priority, and which contains the e default value for each parameter. If you do
not specify a value for a specific parameter, the default value takes effect.
When IKE negotiation begins, the peer that initiates the negotiation sends all of its policies to the remote
peer, and the remote peer searches for a match with its own policies, in priority order.
A match between IKE policies exists if they have the same encryption, hash, authentication, and
Diffie-Hellman values, and an SA lifetime less than or equal to the lifetime in the policy sent. If the
lifetimes are not identical, the shorter lifetime—from the remote peer policy—applies. If no match
exists, IKE refuses negotiation and the IKE SA is not established.
Fields
Modes
The following table shows the modes in which this feature is available:
Firewall Mode
Routed
Add/Edit IKE Policy
Fields
Priority #—Type a number to set a priority for the IKE policy. The range is 1 to 65,543, with 1 the highest
priority.
Encryption—Choose an encryption method. This is a symmetric encryption method that protects data
transmitted between two IPsec peers.The choices follow:
des
3des
aes
aes-192
aes-256
OL-20339-01
A limit for how long the adaptive security appliance uses an encryption key before replacing it.
Policies—Displays parameter settings for each configured IKE policy.
Priority #—Shows the priority of the policy.
Encryption—Shows the encryption method.
Hash—Shows the has algorithm.
D-H Group—Shows the Diffie-Hellman group.
Authentication—Shows the authentication method.
Lifetime (secs)—Shows the SA lifetime in seconds.
Add/Edit/Delete—Click to add, edit, or delete an IKE policy.
Security Context
Transparent Single
56-bit DES-CBC. Less secure but faster than the alternatives. The default.
168-bit Triple DES.
128-bit AES.
192-bit AES.
256-bit AES.
Multiple
Context
System
Cisco ASA 5500 Series Configuration Guide using ASDM
Creating IKE Policies
63-5

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Asa 5510Asa 5540Asa 5520Asa 5550Asa 5580

Table of Contents