Hello dear colleagues, according to the documentation, there is a limitation for IKE gateways: All IKE gateways configured on the same interface or local IP address must use the same crypto profile. (c) The same restriction is mentioned in the PANOS v8.1 course. First of all, it seems strange that we cannot use different IKE options for different peers. Second, I use different IKE Crypto Profiles for different IKE gateways on the same public interface without any problem. I can see that they do use different algorithms for encrypting, hashing, DH group, etc. So it works. Is it some obsolete information they just forgot to remove? Regards, Vladimir Stepanov
... View more