cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
380
Views
0
Helpful
2
Replies

IKE Phase1 Main Mode Mesaages : Does Authentication happens first or last ?

Hi,

Some say the vpn peers authenticate first and then start the process of building the ISAKMP tunnel.

However most book/blog-posts say authentication happens in 5th & 6th packet using the encrypted hash of the pre-shared key.Is this right?

So what is the correct order?

Also tell me if digital certificates are send in plain text or encrypted?

2 Replies 2

Hello.

Main mode use 6-steps process and authentication happens on last steps.

In aggressive mode (3-steps) authentication happens from the very beginning and it's recommended (safe) for PKI authentication only.

Certificates (X.509) may be a part of the message; but only open-keys, so there is no risk if the message is intercepted.

Hi,

Thanks for the reply.

Do we use the shared secret generated after 4th packet to encrypt the hash of the pre-shared keys.

Regards.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card