Got it

IPsec VPN IKE Version

Created: Jan 30, 2021 09:15:43Latest reply: Sep 19, 2021 07:13:53 452 3 0 0 0
  Rewarded HiCoins: 0 (problem resolved)

Hello everyone,

IKE negotiation is an important condition for establishing an IPSec VPN. The IKE version is the key to successful IKE negotiation.

How to select the IKE version when the IPsec VPN is configured on the USG6000?

Please help me! Thank you!


Featured Answers
DDSN
Admin Created Jan 30, 2021 09:16:06

Hi Rengar,

1. When IPsec VPN is configured on the USG6000, the IKE version can be V1, V2, or V1 and V2. If you select V1, only IKE V1 is supported. If V2 is selected, only IKE V2 is supported. If both V1 and V2 are selected and if the device uses IKE V2 to initiate negotiation, both V1 and V2 are supported when the device receives a response from the peer end.

2. For a point-to-point IPsec VPN, the IKE versions at the two ends can be configured as follows:

Network A (IKE V1) ---- Network B (IKE V1) // V1 at one end and V1 and V2 at the other end are not allowed. (If IKE V2 is used to initiate a negotiation, the peer end does not support it.)

   Network A (IKE V2) ---- Network B (IKE V2 or V1 and V2)

   Network A (IKE V1 and v2) ---- Network B (IKE V2 or V1 and V2)

3. If the IPsec profile is configured for the headquarters, set the version to V1 and V2 in the IPsec profile regardless of the IKE version that is used to initiate negotiation at branches.

I hope it helps!


View more
  • x
  • convention:

simchamnan
simchamnan Created Sep 19, 2021 07:13:35 (0) (0)
 
All Answers
DDSN
DDSN Admin Created Jan 30, 2021 09:16:06

Hi Rengar,

1. When IPsec VPN is configured on the USG6000, the IKE version can be V1, V2, or V1 and V2. If you select V1, only IKE V1 is supported. If V2 is selected, only IKE V2 is supported. If both V1 and V2 are selected and if the device uses IKE V2 to initiate negotiation, both V1 and V2 are supported when the device receives a response from the peer end.

2. For a point-to-point IPsec VPN, the IKE versions at the two ends can be configured as follows:

Network A (IKE V1) ---- Network B (IKE V1) // V1 at one end and V1 and V2 at the other end are not allowed. (If IKE V2 is used to initiate a negotiation, the peer end does not support it.)

   Network A (IKE V2) ---- Network B (IKE V2 or V1 and V2)

   Network A (IKE V1 and v2) ---- Network B (IKE V2 or V1 and V2)

3. If the IPsec profile is configured for the headquarters, set the version to V1 and V2 in the IPsec profile regardless of the IKE version that is used to initiate negotiation at branches.

I hope it helps!


View more
  • x
  • convention:

simchamnan
simchamnan Created Sep 19, 2021 07:13:35 (0) (0)
 
Good
View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.