12-07-2007 08:25 AM - edited 03-05-2019 07:52 PM
Hey folks,
We're implementing a router-to-router IPSEC VPN using pre-shared keys. How many characters would you use in order to fell as though you have a "strong" pre-shared key?
Also, while testing this in the lab, I noticed that although I have "service password-encryption" enabled, the pre-shared keys show up in plaintext next to my "crypto isakmp key" commands. Any way to hide it?
Thanks,
SM
12-07-2007 08:36 AM
I like to use a minimum of 12 char. mixing it up between upper case, lower case, numeric, and symbols. Just my rule of thumb.
No way to hide the key, sorry. Just use some crazy, long key that makes no sense. Heck, but the word ENCRYPTED before or after it as well and you'll really confuse someone!!! :)
-brad
(please rate the post if this helps!)
12-07-2007 09:21 AM
Mostly the key length is kept a minimum of 8 characters alpha-numeric
Brad, you can now hide the key with the AES encryption.
HTH
Narayan
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide