IPSec
When configuring a crypto map i have the choice to configure either
Ipsec-isakmp or Ipsec-manual, what is the difference?
I'm thinking if i use manual i configure a transform-set to negotiate the SAs.If i pick isakmp the IKE phase 1 will negotiate the SAs.Is this correct? If it is correct i dont see why there are two different ways to do the same thing? Either way i must configure on the router so where is the benifit to use Isakmp?
My understanding of what i read which could be wrong as it doesnt make sense to me is that both these are used together,IKE phase one negotiates the IKE SA's, and in phase 2, IP Sec uses transform-sets to negotiate the IP Sec SAs.
But even this way i have no idea why 2 negotiations are needed.
What am i missing here? Can someone clarify?
Ipsec-isakmp or Ipsec-manual, what is the difference?
I'm thinking if i use manual i configure a transform-set to negotiate the SAs.If i pick isakmp the IKE phase 1 will negotiate the SAs.Is this correct? If it is correct i dont see why there are two different ways to do the same thing? Either way i must configure on the router so where is the benifit to use Isakmp?
My understanding of what i read which could be wrong as it doesnt make sense to me is that both these are used together,IKE phase one negotiates the IKE SA's, and in phase 2, IP Sec uses transform-sets to negotiate the IP Sec SAs.
But even this way i have no idea why 2 negotiations are needed.
What am i missing here? Can someone clarify?
Networking, sometimes i love it, mostly i hate it.Its all about the $$$$
Comments
-
mikej412 Member Posts: 10,086 ■■■■■■■■■■ed_the_lad wrote:When configuring a crypto map i have the choice to configure either
Ipsec-isakmp or Ipsec-manual, what is the difference?ed_the_lad wrote:I'm thinking if i use manual i configure a transform-set to negotiate the SAs.If i pick isakmp the IKE phase 1 will negotiate the SAs.Is this correct?ed_the_lad wrote:If it is correct i dont see why there are two different ways to do the same thing?ed_the_lad wrote:Either way i must configure on the router so where is the benifit to use Isakmp?ed_the_lad wrote:My understanding of what i read which could be wrong as it doesnt make sense to me is that both these are used together,IKE phase one negotiates the IKE SA's, and in phase 2, IP Sec uses transform-sets to negotiate the IP Sec SAs.
But even this way i have no idea why 2 negotiations are needed.
What am i missing here? Can someone clarify?:mike: Cisco Certifications -- Collect the Entire Set! -
EdTheLad Member Posts: 2,111 ■■■■□□□□□□Thanks Mike, nice analogy at the end.It's finally clicked again.I did know this stuff when i took the bcran but without any hands on i've forgotten all.
Watching a knet video was the last resort and that and your explaination has done the trick.Cisco press does a lousy job on this and the cisco training notes even worse.Networking, sometimes i love it, mostly i hate it.Its all about the $$$$