Header
Home | Set as homepage | Add to favorites
  Search the Site     » Advanced Search
Sections
Syndication


Blogroll:

||||| ALL Cisco-Network ARTICLES |||||  
CCIE Journey,
The CCIE Journey,


Peer Authentication

Sep 25,2009 by alperen

image

Peer Authentication

Would-be IPSec peers must authenticate themselves to each other before IKE can proceed. IKE Phase One has three methods to authenticate IPSec peers in Cisco products. The two peers must negotiate a common authentication protocol from the following choices:

  • Preshared keys—A key value entered into each peer manually (out of band) and used to authenticate the peer.

  • RSA signatures—Uses a digital certificate authenticated by an RSA signature.

  • RSA encrypted nonces—Uses RSA encryption to encrypt a nonce value (a random number generated by the peer) and other values.

A common value used by all authentication methods to help identify the peer is the peer identity (ID). Some ID values include the peer’s IP address or their FQDN, such as ian.testco.com.


168 times read

Related news

» IPSec with CAs
by alperen posted on Sep 29,2009
» Main Mode
by alperen posted on Sep 25,2009
» Preshared Key Authentication
by alperen posted on Sep 25,2009
» Peer groups
by alperen posted on Dec 01,2008
» RSA Signature Authentication
by alperen posted on Sep 25,2009
Did you enjoy this article?
(total 0 votes)

comment Comments (0 posted) 

More Top News
CCSP-Cisco Certified Security Professional
Most Popular
Most Commented
Featured Author