We're Sorry, Full Content Access is for Members Only...

If you like to keep on reading, Become a Member Now! Here is why:

  • Learn any CCNA, CCNP and CCIE R&S Topic. Explained As Simple As Possible.
  • Try for Just $1. The Best Dollar You've Ever Spent on Your Cisco Career!
  • Full Access to our 651 Lessons. More Lessons Added Every Week!
  • Content created by Rene Molenaar (CCIE #41726)

451 Sign Ups in the last 30 days

100% Satisfaction Guaranteed!
You may cancel your monthly membership at any time.
No Questions Asked!

Tags: , , ,

Forum Replies

  1. Hi Rene,

    When would one use IKEv2 over IKEv1? What are the main differences in using one over the other?


  2. Hi Rob,

    Nowadays you should always use IKEv2 (if possible). It supports a couple of things that IKEv1 doesn’t.

    - IKEv2 uses fewer messages than IKEv1 to establish the tunnel and uses less bandwidth.
    - IKEv2 has built-in support for NAT traversal.
    - IKEv2 has a built-in keepalive mechanism (Dead Peer Detection).
    - IKEv2 supports EAP authentication.
    - IKEv2 has some built-in mechanisms against DoS attacks.

    In short, there’s no reason to use IKEv1 anymore unless you have older equipment that doesn’t support IKEv2 for some reason.


  3. hello Rene,

    Is there any possibiltity you create any post about ssl/tls tecnology??


  4. Hello UMER

    To answer your question, it really depends on what you want to do. I am assuming first of all that you are using ASA 8.X (although I believe with relative certainty that the following is supported for 9.X as well). Also, I am assuming that these tunnels are to different vendors. This is important because according to Cisco “Multiple peers used for redundancy is not supported with IKEv2 on the ASA.” Only IKEv1 supports this. So if these tunnels are redundant tunnels to the same vendor, don’t migrate to IKEv2.

    Now, when you use the migration comma

    ... Continue reading in our forum

33 more replies! Ask a question or join the discussion by visiting our Community Forum