Hi Rengar,
1. When IPsec VPN is configured on the USG6000, the IKE version can be V1, V2, or V1 and V2. If you select V1, only IKE V1 is supported. If V2 is selected, only IKE V2 is supported. If both V1 and V2 are selected and if the device uses IKE V2 to initiate negotiation, both V1 and V2 are supported when the device receives a response from the peer end.
2. For a point-to-point IPsec VPN, the IKE versions at the two ends can be configured as follows:
Network A (IKE V1) ---- Network B (IKE V1) // V1 at one end and V1 and V2 at the other end are not allowed. (If IKE V2 is used to initiate a negotiation, the peer end does not support it.)
Network A (IKE V2) ---- Network B (IKE V2 or V1 and V2)
Network A (IKE V1 and v2) ---- Network B (IKE V2 or V1 and V2)
3. If the IPsec profile is configured for the headquarters, set the version to V1 and V2 in the IPsec profile regardless of the IKE version that is used to initiate negotiation at branches.
I hope it helps!