

Ikev2 local-authentication pre-shared-key. Ikev2 remote-authentication pre-shared-key.

Set security-association lifetime seconds 3600 Set security-association lifetime kilobytes unlimited Protocol esp encryption aes-256 aes-192 aesĬrypto ipsec profile IPSEC-PROFILE-AMS1-VPN2 Set security zones security-zone ZONE-VPN interfaces st0.7 host-inbound-traffic protocols bgp Set security zones security-zone ZONE-VPN interfaces st0.7 host-inbound-traffic system-services traceroute Set security zones security-zone ZONE-VPN interfaces st0.7 host-inbound-traffic system-services ike Set security zones security-zone ZONE-VPN interfaces st0.7 host-inbound-traffic system-services ping Set interfaces st0 unit 7 family inet address 169.254.100.1/30 Set interfaces st0 unit 7 family inet mtu 1436 Set interfaces st0 unit 7 description "ASA An圜onnect router" Set security ipsec vpn VPN-ASA establish-tunnels immediately Set security ipsec vpn VPN-ASA ike ipsec-policy SHA256-AES128-3600-14-policy Set security ipsec vpn VPN-ASA ike gateway GW-ASA Set security ipsec vpn VPN-ASA vpn-monitor destination-ip 169.254.100.2 Set security ipsec vpn VPN-ASA vpn-monitor source-interface st0.7 Set security ipsec vpn VPN-ASA df-bit clear Set security ipsec vpn VPN-ASA bind-interface st0.7 Set security ike gateway GW-ASA version v2-only Set security ike gateway GW-ASA external-interface ae0.4 Set security ike gateway GW-ASA local-identity inet 198.51.100.2 Set security ike gateway GW-ASA dead-peer-detection threshold 3 Set security ike gateway GW-ASA dead-peer-detection interval 10 Set security ike gateway GW-ASA address 192.0.2.2

Set security ike gateway GW-ASA ike-policy IKE-ASA Set security ike policy IKE-ASA pre-shared-key ascii-text. Set security ike policy IKE-ASA proposals SHA256-AES128-5-86400
