Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2SecurityMedium

A network engineer is troubleshooting a site-to-site IPsec VPN tunnel between two Cisco routers. Users at the remote site are unable to access resources at the main site, but the phase 1 IKEv2 security association (SA) is established. Upon checking the crypto isakmp sa command output, the engineer notices that the phase 2 IPsec SAs are not being established. Which component is most likely misconfigured, preventing the phase 2 SA establishment?

  1. APre-shared key
  2. BISAKMP policy
  3. CCrypto map transform set
  4. DIKEv2 proposal
Show answer & explanation

Correct answer: C. Crypto map transform set

If Phase 1 (IKEv2 SA) is established but Phase 2 (IPsec SA) is not, the issue typically lies with the IPsec specific configuration, which includes the transform set. The transform set defines the security protocols and algorithms for IPsec data protection (ESP/AH, encryption, hashing), and mismatches here prevent Phase 2 from forming.

Why the other options are wrong

  • A. A pre-shared key mismatch would prevent Phase 1 from establishing.
  • B. An ISAKMP policy (IKEv1) or IKEv2 profile defines Phase 1 parameters; mismatches here prevent Phase 1.
  • D. An IKEv2 proposal mismatch would prevent Phase 1 from establishing.

IPsec Transform Set

A combination of IPsec security protocols and algorithms that defines how traffic is protected in an IPsec Phase 2 Security Association (SA).

  • Specifies the Authentication Header (AH) or Encapsulating Security Payload (ESP) protocol.
  • Defines encryption algorithms (e.g., AES, 3DES) and hashing algorithms (e.g., SHA, MD5).
  • Both VPN peers must have identical transform sets configured for Phase 2 to establish.
  • Part of the crypto map configuration.

Memory trick: Phase One is Key, Phase Two is Transform

More Security questions