Solved

Cisco  2821 and 1841 encr aes 256

Posted on 2013-01-05
8
750 Views
Last Modified: 2013-01-07
Hi,


Righ now, I have 3 sites connected using cisco hardware (837, 1841 and 2821).All of them using ipsed 3des tunnels like a triangle, 3 sites.

The side built using 1841 and 2821 should be changed from 3des to aes but this is the config:

crypto isakmp policy 20
 encr 3des
 authentication pre-share
 group 2
 lifetime 28800

Open in new window


This is used by all the crypto config, and then the specific config for each site

As far as I knowm this entry must be changed to "encr aes 256", but If I do this, 3des sites does not work.

Any idea?

regards
0
Comment
Question by:heze54
  • 4
  • 2
  • 2
8 Comments
 
LVL 15

Accepted Solution

by:
Frabble earned 500 total points
ID: 38746796
You can have multiple IKE policies, the number being the priority and the order that the policies are presented when devices negotiate to find a common policy.

For example, you could configure:
crypto isakmp policy 10
 encryption aes 256
 authentication pre-share
 group 2
 lifetime 28800

This will be tried first and used for the aes sites, but drop down to the next policy (the one you currently have) for the the 3des sites.
0
 

Author Comment

by:heze54
ID: 38747082
Hi,

 then, I understand the following:

crypto isakmp policy 10
 encryption aes 256
 authentication pre-share
 group 2
 lifetime 28800

crypto isakmp policy 20
 encr 3des
 authentication pre-share
 group 2
 lifetime 28800


And, with this new config and making some new changes at crypto ipsec transform-set point, doesn´t it?
0
 
LVL 15

Expert Comment

by:Frabble
ID: 38747420
If you want to use AES for phase 2 then create another transform set, for example:
crypto  ipsec  transform-set  ESP-AES-256-SHA  esp-aes 256  esp-sha-hmac
and use this in the crypto map for the AES site to site tunnels.
0
Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

 

Author Closing Comment

by:heze54
ID: 38750234
A++
0
 

Author Comment

by:heze54
ID: 38750242
Hi again,

According to this text/link

http://www.cs.wustl.edu/~jain/cse567-06/ftp/encryption_perf/index.html

I´m looking for a  stronger encryption algorithm than 3des and also fast and with less CPU workload.

Is this algorithm aes 128,196,256,BF? or what?

regards
0
 
LVL 17

Expert Comment

by:TimotiSt
ID: 38751349
Depends on your usage and security needs. AES128 is a lot better than 3des, while eating less CPU than AES256. BF is also nice, but a lot less standard.

Tamas
0
 

Author Comment

by:heze54
ID: 38752326
Hi,

And aes128 security?
Any doc to compare aes versions? A newer docu about this ?

Regards
0
 
LVL 17

Expert Comment

by:TimotiSt
ID: 38752630
You can find 1000s of pages on comparisons of the AES variants.

AES128 is used by most financial institutions to protect their on-line presence, including PayPal, eBay, all the banks I have accounts with in Hungary and Ireland, etc.

It's your decision if that is good enough for you, or you want super-military-grade encryption, like AES512 with DH group 14.

You can always get better (if your software/hardware supports it), but you pay for it in speed.

Tamas
0

Featured Post

VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Accessing two networks from one PC 30 110
Auto-launch VPN via Wifi 7 49
Connection Dropouts to Database on Windows Server 2008 R2 DFS 12 20
Public DNS  Vs BGP 20 25
When it comes to security, there are always trade-offs between security and convenience/ease of administration. This article examines some of the main pros and cons of using key authentication vs password authentication for hosting an SFTP server.
In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

860 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question