Hi, Dnyaneshwar,

If I look at page 29-6 in the ASA 8.0 Command LIne configuration guide (http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/asa80cfg.pdf ) ,  it only describes how to enable ISAKMP on an interface, disable aggressive mode and setting the ID method for ISAKMP peers.

As kings stated, the isakmp negotation depends on the VPN technology used and whether the asa initiates the isakmp session or receives it. 
But there is an option in the ASA to disable aggressive mode (although it's faster, it's 'less' secure), and only use main mode.
I know that some vendors prefer aggressive mode, also for site-to-site vpn's, for which my opinion is not to do that, unless you use certificates. Otherwise it's impossible to do peer identification check.

So if you disable agressive mode, it might be impossible to setup certain IPSEC site-to-site with other vendors and it will certainly be impossible to use Cisco VPN client and EZVPN with pre-shared-keys for the groups..

But could it be that you're reading a different configuration guide, in which page 29-6 is inside a chapter that describes the configuration of EZVPN?

Kind regards,
Pieter-Jan

On 10 sep 2009, at 09:20, Dnyaneshwar Gore wrote:

Hi Kings,
 
I am also thinking same but as per ASA ver 8.0 configuration guide on page 29-6, its aggressive mode!!!!!
 
Do u have any idea about this?
 
Regards,
D.M.Gore

On Thu, Sep 10, 2009 at 12:32 PM, Kingsley Charles <[email protected]> wrote:
Hi D.M.Gore
 
If I remember correctly, for site to site VPN, it's Main mode and for EzVPN it's aggresive mode.
 
With regards
Kings

On Thu, Sep 10, 2009 at 11:07 AM, Dnyaneshwar Gore <[email protected]> wrote:
Hi All,
 
This is very basic question but I am little bit confused about default mode for phase 1 in IKE negotiation. In some document I read that Main mode is default but in ASA ver 8.0 configuration mode on page 29-6, it says Aggressive mode as default.
 
So not sure which one is correct?
 
Also for router VPN, I think Main mode is default.
 
Kindly express your thought on this.
 
 
Regards,
D.M.Gore

_______________________________________________
For more information regarding industry leading CCIE Lab training, please visit www.ipexpert.com



_______________________________________________
For more information regarding industry leading CCIE Lab training, please visit www.ipexpert.com

---

Nefkens Advies

Enk 26

4214 DD Vuren

The Netherlands


Tel: +31 183 634730

Fax: +31 183 690113

Cell: +31 654 323221

Email: [email protected]

Web: http://www.nefkensadvies.nl/


 Think before you print.




_______________________________________________
For more information regarding industry leading CCIE Lab training, please visit 
www.ipexpert.com

Reply via email to