IPSec profile operation with more than one crypto isakmp policy
When configuring IPSec profiles and crypto policies, you assign a policy number to a particular crypto isakmp policy. For example:
R1(config)#crypto isakmp policy 1
If you have multiple isakmp policies, during negotiation, the device will attempt to use apply the policies in sequential order. If the parameters of the first policy fail to be negotiated with the remote peer, then the next policy will be attempted, until a successful negotiation takes place.
Links
https://forum.networklessons.com/t/ipsec-internet-protocol-security/1281/95?u=lagapides
https://networklessons.com/cisco/ccie-enterprise-infrastructure/ipsec-internet-protocol-security/