IKEv2 Configuration Payload Tidbit

In this tidbit I want to cover what IKEv2 configuration payloads are & why they are needed. So it is sometimes desirable for the hub in hub & spoke topologies to provide configuration data to the spokes. Note that the use of the configuration payload feature is completely optional.


To start, these configuration payloads are a part of messages 3 & 4 during IKE_AUTH. If using the config payload, note that this feature this occurs prior to creating any child SAs.


Now let's cover config payload types so we have an understanding of how communication works:

  • CFG_REQUEST: Sent by the initiator, when the initiator is the FlexVPN client.

  • CFG_REPLY: Sent by the responder, when the responder receives the CFG_REQUEST.

  • CFG_SET: Sent by the initiator when you enable the config-exchange set send command in the IKEv2 profile. Sent by the responder when the CFG_REQUEST is not received, the configuration data is available, and the config-exchange set send command is enabled in the IKEv2 profile.

  • CFG_ACK: Sent by the initiator when you enable the config-exchange set accept command in the IKEv2 profile. Sent by the responder when you enable the config-exchange set accept command in the IKEv2 profile.

Here is a brief overview:

To see the IKEv2 Configuration feature in action see other IKEv2 related posts.

Cheers!

0 comments

Recent Posts

See All

Dual Hub FlexVPN Error Tidbit

Sharing an issue that took me some time to troubleshoot & figure out in my dual hub single cloud FlexVPN lab/post (see here: Configuring & Verifying FlexVPN Redundancy with Dual Hub & Single Cloud). S

FlexVPN Redundancy Tidbit

I want to cover the most commonly used FlexVPN redundancy designs since I intend on building out a few scenarios to play with for studying purposes. The most common designs include: Dual cloud approa

Next Hop Resolution Protocol (NHRP) Tidbit

NHRP is an important protocol used with DMVPNs & FlexVPNs that allows spokes to directly connect to other spokes. To break it down further, NHRP is essentially a resolution arp-like protocol that all

#learnITwithCifelli

© 2023 by Train of Thoughts. Proudly created with Wix.com