Sangfor Community»Categories Product Network Secure with next version(NGAF) Does NGAF support IKE ID

Does NGAF support IKE ID

views: 5996 | comments: 5 | added to Favorites 0
Lights on | 提示:支持键盘翻页<-左 右->
    组图打开中,请稍候......
Created: 06 Jun 2018 18:20

Summary:

We need to confirm does NGAF support IKE ID via Ipsec site - to - site VPN

Reply

FAEoTONGoTH Posted 11 Jun 2018 11:49
Hi sir,
     you can find Local ID and Peer ID at

VPN -> IPsec VPN  -> IPsec VPN -> Phase I -> add  -> advance -> Mode -> Aggressive mode

CTI LS Posted 07 Jun 2018 15:39
Hi,

IKEv1 is the most common IPsec VPN. I think the IKE ID is not in IKEv1.
Nitipat Posted 06 Jun 2018 18:28
The IKE identification (IKE ID) is used for validation of VPN peer devices during IKE negotiation. The IKE ID received by the SRX Series device from a remote peer can be an IPv4 or IPv6 address, a hostname, a fully qualified domain name (FQDN), a user FQDN (UFQDN), or a distinguished name (DN). The IKE ID sent by the remote peer needs to match what is expected by the SRX Series device. Otherwise, IKE ID validation fails and the VPN is not established.
Nitipat Posted 06 Jun 2018 18:24
How to configure IKE ID because this feature should be in the IKEv1
CTI LS Posted 06 Jun 2018 18:23
Hi,

Currently Sangfor NGAF supports IKEv1 only.