cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5445
Views
0
Helpful
1
Replies

KEK and TEK key in get VPN???

kamlesh yadav
Level 1
Level 1

                 Dear All,

I am newbie to GET VPN technology. Just wanted to know how the KEK and TEK keys are generated on Key server and how it is distributed to the GMs.

Also how rekey is generated if all the keys has been used?????

1 Reply 1

olpeleri
Cisco Employee
Cisco Employee

KEK represents the encryption  of the control plane [ very similar to the ike phase I]. Usual lifetime 1 day

TEK represents the encryption of the data plane [ aka ipsec phase II] - Usual lifetime 1 or 2 h.

Rekey is always pushed by the key server.

For complete understanding U might have a look at

http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6525/ps9370/ps7180/GETVPN_DIG_version_1_0_External.pdf

Cheers,