Skip to main content
Cisco SD-WAN
Product Documentation
Viptela Documentation


vpn interface ike mode—Configure the mode to use in IKEv1 Diffie-Hellman key exchanges (on vEdge routers only).

Command Hierarchy

vpn vpn-id
  interface ipsecnumber
      mode mode


Exchange Mode
Mode to use for IKEv1 Diffie-Hellman key exchanges. It can be one of the following:
 aggressive—Use IKE aggressive mode to establish an IKE SA. In this mode, an SA is established with the exchange of only three negotiation packets.
 main—Use IKE main mode to establish an IKE SA. In this mode, a total of six negotiation packets are exchanged to establish the SA. This is the default.


Configure aggressive mode for IKEv1 key exchanges:

vEdge(config)# vpn 1 interface ipsec1 ike
vEdge(config-ike)# mode aggressive

Release Information

Command introduced in Viptela Software Release 17.2.​

Additional Information

See the Configuring IKE article for your software release.

  • Was this article helpful?