SIMOS Useful links and tips ASA Anyconnect Double Authentication Link Broker Applet Java/ActiveX (2018) link IKE/IKEv2 Rekey Link FlexVPN "Enrollment Terminal or URL" Link FlexVPN Per-Peer Configration Link NHRP Holdtime and Cache refresk Link Using Hostname in IPsec Site to Site VPNs Link Delete default ISAKMP Policies "no cry isakmp default polic" VPN Authentication CRACK (Public keys/radius) Link Supported Cisco VPN Platforms Link GET PPT (2006) Link CCIE Tutorial Link Online Diffie Hellman Calculator DMVPN Phase 1/2/3 Link Certificate Authority Link "Identity Sent to Peer" Link PFS and Y/N = N in IKE2, (Child SA created at time of Main SA) DMVPNs Cisco Proprietary but a Draft RFC has been produced Link The reasons for creating an empty IPsec profile (defaults) Link "aaa authorization group cert list" explained Using ASA Packet Trace to bring up VPN Link Dead Peer Detection Link Default Transform Set Link DMVPN Explained including NHRP Timeouts Link "ip nhrp map multicast" Link Selecting the profile xml from the Anyconnect window Link FlexVPN correct configuration examples for Spoke to Spoke (Shortcut) "crypto ipsec profile" explained Next Generation and legacy algorithms DMVPNS with PSKs and wildcarding on the IP address HUB config NHRP in FlexVPN and short cutting Spoke-to-Spoke IKEV1 and IKEV2 rekeying Link Controlling traffic within site to site VPN (ACLs and vpn-filter) Wild carding Pre-shared keys for IPSEC "ip flow ingress" explained VTIs and identifying interesting traffic down the tunnel (Lab minutes) ECDSA The digital signature of a better Internet Elliptical Curve Cryptography ECC explained Differences between Posture Module and standalone Host Scan Package Deploying Posture Module and Host Scan packages AES-GCM Explained Galios Pronounced IKE V2 PRF's Seperate process to generate IKEv2 key/hash material ISAKMP Default Policy enable/disable NHRP Explained and keepalives FlexVPN Short Circuit configuration Link Configuring the Tunnel Mode .The encapsulation mode for the tunnel interface defaults to generic route encapsulation (GRE), Migration from DMVPN to FlexVPN (Phased Deployment) IKE V2 & PRF Excellent Cisco Live presentation on FlexVPN FlexVPN using EAP Peer Authentication DMVPN High Availability Sharing IPsec with Tunnel Protection IKEv2 and Legacy Config Filtering on Site to Site VPNs Link