IOS VPN with IKE AM

Hello ,

While I was going through the section for IOS to IOS VPN with PSK across an ASA with NAT and IKE AM , i had a doubt about the description and the steps involved in the task. While creating the ISAKMP PROFILE " AGGRESSIVE " you ask that the following options be enabled.. initiate AM , self-identity and keyring default .. the solution works .. however while looking at the config it says that the ISAKMP profile is incomplete until a " match identity " statement is provided. I found that it works with and without this statement . could someone please let me know as to why the Profile says incomplete and still works as intended without a " Match Identity " statement .

Thanks,

Karthik

 

 

Sign In or Register to comment.