VPN
Configuring the Site-to-Site VPN
Cisco ISA500 Series Integrated Security Appliance Administrator Guide
254
8
NOTE
The DPD should be enabled if you want to use the Redundant
Gateway feature for the IPSec VPN connection.
STEP 6
Click
OK
to save your settings.
STEP 7
Click
Save
to apply your settings.
NOTE
Next Steps:
•
To maintain the IKE policies, click
Site-to-Site -> IKE Policies
. See
Configuring the IPSec IKE Policies, page 254
•
To maintain the Tranform policies, click
Site-to-Site -> Transform Policies
.
See
Configuring the IPSec Transform Policies, page 256
Configuring the IPSec IKE Policies
The Internet Key Exchange (IKE) protocol is a negotiation protocol that includes an
encryption method to protect data and ensure privacy. It is also an authentication
method to verify the identity of devices that are trying to connect to your network.
You can create IKE policies to define the security parameters (such as
authentication of the peer, encryption algorithms, and so forth) to be used for a
VPN tunnel.
NOTE
The security appliance supports up to 16 IKE policies.
STEP 1
Click
VPN
-> Site-to-Site -> IKE Policies
.
The IKE Policies window opens. The default and custom IKE policies are listed in
the table.
STEP 2
To add a new IKE policy, click
Add
.
Other options:
To edit an entry, click
Edit
. To delete an entry, click
Delete
. The
default IKE policy (
DefaultIke
) can not be edited or deleted.