Sunday, July 1, 2018

ISAKMP PSK hashing

So I am new to my company and I was assigned a ticket last week that even though the issue is fixed, I still don't know why. Here is the question:

-My company has vpn connection to client. From my company, we use 2 routers (RT_1 and RT_2) to set up tunnel to client (RT_cl). On RT_1 we config:

crypto isakmp key PSK RT_cl_ip same for RT_2

on RT_cl; we have the following 2 configs:

crypto isakmp key 6 PSK RT_1_ip

crypto isakmp key 6 PSK RT_2_ip

These configs come with correct config for tunnels as well.

The question is, I can see tunnel between RT_cl with RT_1 is formed but not with RT_2. And in order to have the tunnel up, I need to make a modification on RT_2 as follows:

crypto isakmp key 6 PSK RT_cl_ip

My question would be when we need to include hashing method and when we need not? Appreciate your help!



No comments:

Post a Comment