5.1

Table Of Contents
n
If the Cisco device does not accept any of the parameters the vShield Edge sent in step one, the Cisco
device sends the message with flag NO_PROPOSAL_CHOSEN and terminates the negotiation.
3 vShield Edge to Cisco
n
DH key and nonce
4 Cisco to vShield Edge
n
DH key and nonce
5 vShield Edge to Cisco (Encrypted)
n
include ID (PSK)
6 Cisco to vShield Edge (Encrypted)
n
include ID (PSK)
n
If the Cisco device finds that the PSK doesn't match, the Cisco device sends a message with flag
INVALID_ID_INFORMATION; Phase 1 fails.
Phase 2: Quick Mode Transactions
The following transactions occur in sequence between the vShield Edge and a Cisco VPN device in Quick
Mode.
1 vShield Edge to Cisco
:vShield Edge proposes Phase 2 policy to the peer. For example:
Aug 26 12:16:09 weiqing-desktop
pluto[5789]:
"s1-c1" #2: initiating Quick Mode
PSK+ENCRYPT+TUNNEL+PFS+UP+IKEv2ALLOW
{using isakmp#1 msgid:d20849ac
proposal=3DES(3)_192-SHA1(2)_160
pfsgroup=OAKLEY_GROUP_MODP1024}
2 Cisco to vShield Edge
Cisco device sends back NO_PROPOSAL_CHOSEN if it does not find any matching policy for the
proposal. Otherwise, the Cisco device sends the set of parameters chosen.
3 vShield Edge to Cisco
To facilitate debugging, you can turn on IPSec logging on the vShield Edge and enable crypto debug on
Cisco (debug crypto isakmp <level>).
Configuring IPSec VPN Service Example
You must configure VPN parameters and then enable the IPSEC service.
Procedure
1 Configure vShield Edge VPN Parameters Example on page 87
You must configure at least one external IP address on the vShield Edge to provide IPSec VPN service.
2 Enable IPSec VPN Service Example on page 88
You must enable the IPSec VPN service for traffic to flow from the local subnet to the peer subnet.
vShield Administration Guide
86 VMware, Inc.