Header
Home | Set as homepage | Add to favorites
  Search the Site     » Advanced Search
Sections
Syndication


Blogroll:

||||| ALL Cisco-Network ARTICLES |||||  
CCIE Journey,
The CCIE Journey,


Develop the Parameter Preferences

Sep 27,2009 by alperen

image

Develop the Parameter Preferences

To complete the IKE planning process, what would make sense is to create a table of the preferred combination of security features, plus one or more fallback options for those devices or locations that can’t support the preferred package. The resulting table might look like the following:

Parameter

Preferred (stronger)

2nd Choice

3rd Choice

Encryption algorithm

3des

des

des

Hash algorithm

sha

sha

md5

Authentication method

preshare

preshare

preshare

DH key exchange group

2

2

1

IKE SA lifetime

43,200

43,200

86,400

In comparing the two tables, you should see that RSA-SIG would be a preferred authentication method over preshared keys. This chapter deals with using preshared keys, while Chapter 12 covers Certificate Authority (RSA-SIG). RSA encrypted nonces are addressed in the last section of this chapter.


Note 

You can’t use SHA together with DES encryption on Cisco’s VPN software client version 3.6. Part of the problem with determining a set of preferences is being aware of the different platform limitations.

Using our scenario for this chapter, the Preferred column represents our configuration preferences for all North American branches and would be the only options configured. The 2nd Choice column would be for those overseas branches that can support the Preferred configuration, except for the export restriction on triple DES. Assuming they don’t form VPN sessions with anyone else, this would be the only choice configured on those devices. The 3rd Choice column might represent extremely small branches or telecommuters using small personal routers with limited resources and options. This also represents the lowest level of parameter options the main office will accept for a VPN connection. The only device that will have all three choices configured is the main office router.

Because any parameter that isn’t defined will use the existing default value, the actual table could look like the following example. Either table can be used in Task 2 to configure the IKE parameters.

Parameter

Preferred (stronger)

2nd Choice

3rd Choice

Encryption algorithm

3des

   

Hash algorithm

   

md5

Authentication method

preshare

preshare

preshare

DH key exchange group

2

2

 

IKE SA lifetime

43,200

43,200

 

103 times read

Related news

» Task 1—Prepare for IKE and IPSec
by alperen posted on Sep 29,2009
» Step 2-2 Create IKE Policies
by alperen posted on Sep 27,2009
» Step 1-2 Determine the IKE (IKE Phase 1) Policies
by alperen posted on Sep 27,2009
» Task 3—Configure IKE
by alperen posted on Sep 29,2009
» Step 4-1 Display the Configured IKE Policies
by alperen posted on Sep 27,2009
Did you enjoy this article?
(total 0 votes)

comment Comments (0 posted) 

More Top News
CCSP-Cisco Certified Security Professional
Most Popular
Most Commented
Featured Author