What is IKE?

Networking, Wireless Routers (802.11 a/b/g/n/ac/ax WiFi), NAT, LAN configuration, equipment, cabling, hubs, switches, and general network discussion
Post Reply
anaheim99
Member
Posts: 46
Joined: Wed Oct 29, 2003 6:42 pm
Location: o.c.

What is IKE?

Post by anaheim99 »

Hello all, I'm just starting to learn VPN and want to know what does or what is IKE on VPN? Thanks in advance to all.
cyberskye
Senior Member
Posts: 4717
Joined: Wed Jan 10, 2001 12:00 am
Location: DC

Post by cyberskye »

IKE handles authentication and negotiation (which encryption scheme will be used) for IPSec. You could also use SKIP as an alternative but IKE is sorta standard.

Sorta like tcp/ip ... IKE/IPSec or SKIP/IPSec
anything is possible - nothing is free

:wth:
Blisster wrote:It *would* be brokeback bay if I in fact went and hung out with Skye and co (did I mention he is teh hotness?)
:wth:
User avatar
YeOldeStonecat
SG VIP
Posts: 51171
Joined: Mon Jan 15, 2001 12:00 pm
Location: Somewhere along the shoreline in New England

Post by YeOldeStonecat »

Stands for "Internet Key Exchange".
MORNING WOOD Lumber Company
Guinness for Strength!!!
anaheim99
Member
Posts: 46
Joined: Wed Oct 29, 2003 6:42 pm
Location: o.c.

Post by anaheim99 »

thanks for the reply fellows, one more thing I dont understand here, if IKE hadles the authentication and encryption then what does ISAKMP do? Sorry for the stupid question.
cyberskye
Senior Member
Posts: 4717
Joined: Wed Jan 10, 2001 12:00 am
Location: DC

Post by cyberskye »

IKE is the combination of two protocols.

InternetSecurityAssociation_and_KeyManagementProtocol
and
Oakley

As I stated above, IKE provides two functions - negotiation and key exchange.

ISAKMP handles the negotiation (read up on SA, or Security Association) which determines encrypt alogorithms among other things

Oakley handles the key exchange.


It may seem anal, but there are so many point in the 'grapevine' that can be attacked.

Welcome to the flexible world of IPSec.

I would recommend a good book on IPSec and VPNs in general before trying anything. "Inside Network Perimeter Security", NewRiders, is a good book by the SANS folks.


Cheers,

Skye
anything is possible - nothing is free

:wth:
Blisster wrote:It *would* be brokeback bay if I in fact went and hung out with Skye and co (did I mention he is teh hotness?)
:wth:
Post Reply