You are on page 1of 1

Lab: ssl vpn with bookmarks

Simlet: IPSEC VPN between ASA and Router


New D&D: DMVP Spoke Register Process.

1) sanity check ? incorrect pre-share key


2) atts not acceptable ? verify incompatible IPsec transform-set
3) phase 1 MM_NO_STATE ?verify if ISAKMP packets are blocked at ISP
4) pktsencaps:110#pktsdecaps:0 ? verify routing and connectivity
5) packets need to be fragmented but DF set ? verify MTU path discovery
6) QM_IDLE ? verifies successful PHASE1

and I hope this help, the Q�s I remember were something like this:

Which belongs to PKI?


ANS: certificate Authority

What does it mean MSG6 in phase 1 IKEv1?


ANS: initiator checks if PSK hashes match

In the simlet use show crypto ipsec transform-set you will see 2 transforms, match
with the transform used with show crypto ipsec sa
ANS: TSET

exhibit: hub, spoke1, spoke2

Hub
Authentication local rsa
Autenticaci�n remote pre-share ABC

Spoke 1
Authentication local rsa
Authentication remote preshare ABC

Spoke 2
Authentication local preshare CDE
Authentication remote rsa

ANS: wrong authentication method on Spoke 1

You might also like