Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

ike policy

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

ike policy

L4 Transporter

What part of the configuration on the PA matching what is called the ike policy on the Cisco?

22 REPLIES 22

L6 Presenter

Hello Infotech,

It can be configured on following location. Let me know if you have further questions.

IKE.PNG

Regard,

Hardik Shah

L7 Applicator

Hello Infotech,

Ike policy defines different security parameter you are using for your IKE profile. On PAN firewall it's IKE-crypto.

ike-profile-1.jpg

Once, you will configure the IKE profile, then as a second step, you need to configure a IKE-gateway. It will included local IP, peer IP, exit interface, preshared key, Peer ID type etc.

ike-gateway..jpg

Hope this helps.

Thanks

There seem to be more than one policy on the ike policies on the cisco how do I know which one matches the PA?

Hello Infotech,

During the phase 1 negotiation, both gateways will exchange their IKE-crypto details and the common profile would be chosen for tunnel.

Thanks

Hello Infotech,

You may configure Max 3 IKE-crypto profile on PAN and at least one should be matched with CISCO.

Thanks

Unless there is des setup on the cisco and it doesn't appear to be available on the PA.

Hi Infotech,

DES is not secure, we only support 3DES and above protocols.

Regards,

Hardik Shah

I understand that but the cisco is old and I think it may have that option still trying to figure out what ike policy and priorities are and how they relate to the PA

PAN firewall supports bellow mentioned encryption technology for IPsec Phase 1 negotiation:

encryption-tech.jpg

Thanks

Are you saying that aes128 is compatible with des?

No, i mean to say, you have following option to choose for IKE-encryption. It should be identical on both gateways ( PAN---- Cisco).

Thanks

Unless you want to set the PA to does and that option is not available

Since PAN does not support DES, you need to change CISCO IKE-crypto policy accordingly.

Thanks

Yeah there is one part I the cisco side I am trying to verify. The ike policies look like they match but there is something called ike policy priority and I am not 100% sure how to verify that

  • 6699 Views
  • 22 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!