Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

vpn-sharedkey exchange

Hi Team,

I have a small query which is illustrated as given below... Kindly help..

in phase1, we use shared secret key and this is used for the authentication. Are we sending this shared secret key in encrypted format to the other end or how is the exchange actually happens, I would expect a detailed info about this, and not any cisco url. As far as i know, i beleive it uses asymmetric encryption and sends the pubic key... So, during the configuration time, the other end already has the private key for the public key which is sent by this end. Is this the way it works??

thisend.....................................otherend

key=cisco................................key=cisco

pvt-key=cisco...........................pvt-key=cisco

public-key=asdmo.....................public-key=asdmo

this end--

public-keys go in an encrypted format to other end

Also sends a Hash of the same.

so otherend does this as given below ??

1.verifies the hash value received using the hash function.

2.decrypts the publick-keys

3.key recevied = asdmo

4.compares it with its own public-key=asdmo

5.Hence finds a match

pls revert, if you can visualize all these exchanges...

Everyone's tags (1)
1 REPLY
VIP Purple

vpn-sharedkey exchange

If you really want it detailed, the RFC gives you all info you need. And don't worry, it's not that hard if you reserve two or three hours for study. And no, the PSK is never sent over the wire.

Here are the documents you need:

IKEv2: http://tools.ietf.org/html/rfc5996#page-9

ISAKMP: http://tools.ietf.org/html/rfc2408#page-45


--
Don't stop after you've improved your network! Improve the world by lending money to the working poor: http://www.kiva.org/invitedby/karsteni
420
Views
0
Helpful
1
Replies