User's Manual

Table Of Contents
VPN
Configuring the Site-to-Site VPN
Cisco ISA500 Series Integrated Security Appliance Administrator Guide 254
8
NOTE The DPD should be enabled if you want to use the Redundant
Gateway feature for the IPSec VPN connection.
STEP 6 Click OK to save your settings.
STEP 7 Click Save to apply your settings.
NOTE Next Steps:
To maintain the IKE policies, click Site-to-Site -> IKE Policies. See
Configuring the IPSec IKE Policies, page 254.
To maintain the Tranform policies, click Site-to-Site -> Transform Policies.
See Configuring the IPSec Transform Policies, page 256.
Configuring the IPSec IKE Policies
The Internet Key Exchange (IKE) protocol is a negotiation protocol that includes an
encryption method to protect data and ensure privacy. It is also an authentication
method to verify the identity of devices that are trying to connect to your network.
You can create IKE policies to define the security parameters (such as
authentication of the peer, encryption algorithms, and so forth) to be used for a
VPN tunnel.
NOTE The security appliance supports up to 16 IKE policies.
STEP 1 Click VPN -> Site-to-Site -> IKE Policies.
The IKE Policies window opens. The default and custom IKE policies are listed in
the table.
STEP 2 To add a new IKE policy, click Add.
Other options: To edit an entry, click Edit. To delete an entry, click Delete. The
default IKE policy (DefaultIke) can not be edited or deleted.