cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
663
Views
0
Helpful
1
Replies

Best Practice for IKE keys

jaz0nj4ckal
Level 1
Level 1

Folks,

I am configuring my first site-to-site vpn using IPsec and IKE; however, I wanted to know if I should watch out for anything and the best practices for IKE.

I have generated a phrase that is 30 characters long, but should I include “special characters” in my IKE key?

1 Reply 1

Marvin Rhoads
Hall of Fame
Hall of Fame

Rather than the key length and 'strength' I'd focus on keeping a copy documented / stored securely offline somewhere. Process and documentation are at least as important as the technology.

99% of your protection comes from using a VPN at all as opposed to the characters used in your PSK.

If it's an option (e.g ASA 8.4 at both ends) I'd recommend using IKEv2.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: