Cisco ASA Site-to-Site IKEv2 IPSEC VPN

Hello Neil

The configuration of a pre-shared key on the crypto map is optional. As in the lesson, if you don’t specify it, then it won’t be used. In the configuration you are sharing, it is used, and must be applied at both ends of the tunnel. More info on this command can be found here:

Similarly, when creating the tunnel group, you can specify either a symmetric or an asymmetric pre-shared key for ikev2. In the example in the lesson (and in your post), an asymmetric pre-shared key arrangement is being used, where each end of the tunnel uses a different pre-shared key. As you can see in the lesson, the local-authentication preshared key must match the remote-authentication preshared key of the device on the other end of the tunnel. But this too is optional. More on these commands can be found here:

I hope this has been helpful!

Laz