Introduction To Flexvpn: Configuring Internet Key Exchange Version 2 (Ikev2) and Flexvpn Remote Access
Introduction To Flexvpn: Configuring Internet Key Exchange Version 2 (Ikev2) and Flexvpn Remote Access
Introduction To Flexvpn: Configuring Internet Key Exchange Version 2 (Ikev2) and Flexvpn Remote Access
Internet Key Exchange Version 2 (IKEv2), a next-generation key management protocol based on RFC 4306,
is an enhancement of the IKE Protocol. IKEv2 is used for performing mutual authentication and establishing
and maintaining security associations (SAs).
FlexVPN is Cisco's implementation of the IKEv2 standard featuring a unified paradigm and CLI that combines
site to site, remote access, hub and spoke topologies and partial meshes (spoke to spoke direct). FlexVPN
offers a simple but modular framework that extensively uses the tunnel interface paradigm while remaining
compatible with legacy VPN implementations using crypto maps.
This guide contains the following modules:
• Configuring Internet Key Exchange Version 2 (IKEv2) and FlexVPN Remote Access, on page 1
• Configuring FlexVPN Server, on page 2
• Configuring FlexVPN Client, on page 2
• Configuring IKEv2 Load Balancer, on page 2
• Configuring IKEv2 Fragmentation, on page 2
• Configuring IKEv2 Reconnect, on page 2
• Configuring IKEv2 Packet of Disconnect, on page 2
• Configuring IKEv2 Change of Authorization Support, on page 2
• Configuring Aggregate Authentication, on page 2
• Appendix: FlexVPN RADIUS Attributes, on page 3
• Appendix: IKEv2 and Legacy VPNs, on page 3
Introduction to FlexVPN
1
Introduction to FlexVPN
Configuring FlexVPN Server
Introduction to FlexVPN
2
Introduction to FlexVPN
Appendix: FlexVPN RADIUS Attributes
authentication method to establish a secure tunnel over the Internet between Cisco AnyConnect client and
FlexVPN server.
Introduction to FlexVPN
3
Introduction to FlexVPN
Appendix: IKEv2 and Legacy VPNs
Introduction to FlexVPN
4