Question about encryption for a VPN established between two of our sites

We have two routers Cisco 2951, one at our main location and one at a branch.  An engineer for a local company came and worked all the parameters, including the VPN between the two men.

For an upcoming exam, the firm wanted to know what kind of security/encryption has been implemented between the two routers.  The engineer is no longer available, so I've went over our configuration files for each of the routers and will have questions about what to tell them (I'll be the first to admit that some of this stuff is over my head).

I enclose the portions of the configs with "crypto" information he put in place.  If you see something wrong, or need something extra, let me know.

Thanks in advance!

That's what you use:

Phase 1: 3DES, SHA1, PSK, Group2 DH (1024 bits), life time 86400 s

Phase2: 3DES, SHA1

Which is today considered legacy crypto, but probably nothing to worry. The crypto-config has always considered that there is "room for improvement"...

Tags: Cisco Security

Similar Questions

  • How to write a query for the data exchange between two columns?

    How to write a query for the data exchange between two columns?

    I tried a request, does NOT work.
    update tmp t1 set t1.m1=t1.m2 and t1.m2=(select t2.m1 from tmp t2 where t2.student_id = t1.student_id)
    Thank you.

    Published by: user533361 on October 23, 2009 14:04

    Just plain and simple:

    update tmp t1
     set t1.m1=t1.m2,
         t1.m2=t1.m1
    /
    

    SY.

  • Update fails. Thank you for your interest to get updates of our site. ___

    That's what I see when I hit windows update in the start menu:

    Thank you for your interest to get updates of our site.

    This site is designed to work with Microsoft Windows operating systems only.

    To search for updates of Microsoft products are designed for Macintosh operating systems, please visit http://www.microsoft.com/mac/.

    I am running a version of ligitimate support windows xp center edition and for some reason, this thing think I have mac or a mac on my pc operating system. I had installed, "Bumptop" but I've always had updates when they were available. And I was still able to check updates but now after uninstalling the "Bumptop", I'm having this problem. So the question: what could be the problem and what is a possible fix?

    Check out it:

    Windows Update page says "thank you for your interest to get updates of our site."
    http://www.Winhelponline.com/articles/35/1/

    TaurArian [MVP] 2005-2010 - Update Services

  • Question about support for LabVIEW DLLS and Unicode

    Hello

    I have a question about LabVIEW and DLL functions calls.

    I use a DLL (sorry, I can't share it) that was written in C. It was written to support Unicode and non-Unicode function calls.

    The Unicode function is valid, then FunctionNameW is called if FunctionNameA is called.

    I am building a few VI to access the library. I have the regular functions of FunctionNameA work.

    My question is, does LabVIEW support versions of function FunctionNameW Unicode, and if so is it necessary Although LabVIEW is already working with the standard function call?

    Am I being redundant or what should I build in Unicode support?

    The first time I tried to test the Unicode functions, I had an error, and I guess this is a system setting.

    Thank you for your time in advance.

    DB_IQ wrote:

    I don't think I have TO implement the Unicode, but I want if I can.

    For what I do, I think almost it is not serious. But I wanted to know if it could be used.

    The short answer is "Yes, you can do it."  However, it may open a new Pandora's box.  If you're not careful, problems and complications that can still spread to other projects that are not using Unicode!  It is better not to summon this monster unless there is absolutely no other way to do the job.

  • How backup VPN configuration between two universities?

    Hello, I am a student of the Greece and I have a graduation project to configure Backup VPN between two universities. Principal of communication made with leased lines. I study a lot, but now that it's time for implementation I have some thoughts:

    -What hardware and software IOS do I need? Cisco 1841 it is ok for A & D routers?

    -Use GRE IPSec transport mode or IPsec Tunnel mode?

    -What will be the failover mechanism for switching traffic lines leased to IP VPN Backup and opposite? A teacher told me something about the Interface Prioritys. I read somewhere that this is done with the such as EIGRP routing protocol. who was right the Professor or the book?  :-D

    -In the same place, they have Firewall and NAT, I need to do any action for this?

    The attached file contains topology I want to implement

    'My' talk site 1

    2 a Central Site

    E communicates with A, but no traffic is to A of E with normal circumstances. Subnet on E access Internet through F, then press D.    VPN will be implemented on the LAN but the specific source E traffic will pass through the Backdoor VPN (I think that the solution to this is ACL on the router). They have no routing protocol in 'my' site A directly connected routers and the default routes.

    How imlement this?

    I think the first thing to do is A to D connectivity

    I will try to do this to tracers package first, but how can ' I imitate the SP network?

    I need help I can get!

    Hi John,.

    In our scenario, given that our main connection is a direct leased line between E and F, so I guess there is no other network between the two routers. In this case we do not need to configure SLA monitoring or any interface a priority. We can simply enter two default routes:

    IP route

    IP route 254

    In this scenario, if the leased line interface goes down, the second default route is used and the traffic should be routed by A router.

    SLA monitoring monitors connection (using the ping tests) by one of the interfaces of the router, and when we are not able to ping from one server (specified in the configuration of the SLA) through the interface, then we change the default track to track traffic through some other interface.

    So, in your scenario, we can monitor the connection between E and F, and when the link goes down, we can change the default route to point a.

    This is useful in the scenario where we have another ISP connection as our primary connection.

    Here is a link on how to configure SLA monitoring on the router:

    http://www.Cisco.com/en/us/docs/iOS/12_4/ip_sla/configuration/guide/hsicmp.html

    After you have configured the SLA followed by using the link above, you can bind it to the default route by using the following command line:

    track road IP / / default main route

    IP route 255 / / default route with a metric of higer that comes into play when the main default route goes down

    In addition, the sample configuration that you give in the doc is almost correct, defined transformation is missing just a hashing algorithm. Here is a link with an example for a tunnel from lan-to-lan between two routers:

    http://www.Cisco.com/en/us/partner/products/HW/routers/ps221/products_configuration_example09186a008073e078.shtml

  • Question about encryption keys for TP server 8710

    I'm discovering the activation process of encryption keys for my telepresence server clusters.

    I know that we need this encryption key (L-AESCDN7-K9).  We need one per frame, or one per blade?

    The encryption key is installed directly on each Blade Server, as you would apply the key to each of them.  Each server blade has its own twist.

  • 3 questions about encryption on the Z5

    Hi, I have three questions to ask other Xperia users.

    If I decide to encrypt my phone (Z5):

    (1) what will be the star of the performance? It will be noticeable?

    (2) I know it is not compatible with the smart lock, but it will make it also impossible to unlock the phone by using the fingerprint reader, knowing that this feature uses a proprietary API in its current form of "Lollipop"? (Good thing Marshmallow natively supports it)

    (3) again, it will be possible to use and update my phone with Flashtool?

    Thank you

    Hey, I have improved my Z5P yesterday to 6.0 using flashtool, so I can help

    (1) not for me / I have no comparison

    (2) totally compatible. Fingerprints don't worked with LL, as well as with mm. Fingerprint req. a code pin or password then, no reason

    (3) totally, Yes. BUT: I have my sdcard BA. Well, and not have suffered in some way the cryptokey erased (something like that), so I had to restore a backup that I did the day before. The files are always there, they just cannot be opened. Memory as before interior work, without loss of data.

    Cheers.

  • question about size for android devices

    Hello, I created an app for the ipad and I want the same app for android, my question is about the size.

    What zize I must set in indesign to create the application for android devices? or can I use the same (size of the ipad) and the app will be resised for all devices?

    Thank you

    If you are using 1024 x 768 and PDF that should work for almost any device of Tablet.

    You can visit this page for compatibility with non - iOS feature devices: http://helpx.adobe.com/digital-publishing-suite/help/supported-feature-list.html

  • A Question about catalyst for a fool to programming

    I don't know anything about programming and I don't want to. I am a photographer and videographer. Programming is not my thing. That being said, I have messed around catalyst and I love how it is easy to make nice looking pages interactive and such.

    Now for the question. Can I use just the catalyst (as in any other software is necessary) to build a website for my company or I need, say, Dreamweaver too?

    So, can I build a Web site using only Flash Catalyst.

    Thanks in advance.

    How Adobe Flash Catalyst advertising, is that you don't need to know programming. I still run across problems where the only way to go into the code and change it. So, my impression is that simple Web sites can be designed using Flash Catalyst or it can be used for more complex interfaces quickly prototype which then need to be filled in the code section.

    Yes, you can design an entire website with Flash Catalyst. That's what I intend to do (with some codes html in addition to him) with my Web site. You initially design in Photoshop or Illustrator.

    I hope this helps.

  • Questions about memory for Mac beginning of 2008

    Someone at - he used the Adamante memory in all their machines?  Available on Amazon 16 GB(2x8) 249 more 5.61 hii - 255,000 Macsales has their image on sale now for $279, usually $299

    Upgrade of RAM Apple Adamanta 16 GB (2x8GB) for Apple Mac Pro early 2008 (8 cores) 2.8 GHz CPU MA970LL/A DDR2 800 MHz PC2-6400 ECC Fully Buffered 2Rx4 CL6 1.8V FBDIMM

    by Adamanta memory

    Adamanta has a lot of memory on their site, but I think they mainly sell through Amazon

    Question # 2

    I'm looking at the specs on my early 2008 and noticed that the motherboard has 8 slots for memory-what is it for and why they are not met?

    Better buy RAM by Crucial > http://www.crucial.com/usa/en/memory-info?cm_re=top-nav-_-flyout-memory-_-us-mem ory

    I highly recommend them for the RAM.

  • Question about batteries for laptops and a station (HP Elitebook 840)

    Hello

    I have a question for plagging the laptop to the docking station and battery, basically my main concern is not to connect to the laptop to run a/c, while it is fully charged and I'm always load only up to 100% and then when it reaches the minmum load then I connect it comes back to a/c, so my question here

    So do you think that that plug the laptop into the docking station will not decrease the duration of battery life because it will always be in charge mode?

    Thank you.

    After this announcement, I made a simple google image search with different keywords before 'docking and battery' and I found the following thread that answers my question

    Docking station ruin the battery?

    http://h30434.www3.HP.com/T5/notebook-hardware/is-docking-station-ruining-the-battery/TD-p/3249345

    Thank you rcspencer

    Thank you.

  • Question about RAM for eMachines 633ids

    Hello

    Just bought an eMachines 633ids work today. The PC is old and it came with 64 MB of SDRAM. I have an eMachines broken T1742 with 128 MB of RAM. I was wondering if I could put the T1742 broken in the new 633ids RAM. It will work and is it safe? I don't know if RAM of the broken T1742 is good because the motherboard is shot. Do I just buy new RAM for the 633? If so I wouldn't mind putting money into it because it is in perfect condition. I paid $15 for it.

    Thank you.

    Don

    They wont even fit (see shears) the good news is the ram for 633ids (128 MB which is max) when you can find it (google it) is about $20

  • Question about fiber for 2911 modulus

    Hello

    I am kinda new in the world of fiber and would welcome some guidance on how to proceed on some confusion I have.

    We have an access provider that is given to the connection in single-mode fiber (LX) to 10 Mbps with a ST connector. We have a 2911 on site and I did some research on the modules and found the GLC - FE - 100LX module. So my question is this would not negotiate or I would be able to set the speed to 10 MB? IM assuming that this module is a connector LC so just need a cable to LC single mode fiber ST?

    Thank you for your help.

    I would check with the ISP if they actually give you a strangled 10 MB 100Mb connection.  An optical interface 10Mb is not very common these days.  100 MB transceivers not to negotiate at 10 Mb/s.

  • Question about license for upgrade of stand-alone LR6, mine says creative cloud

    I bought the upgraded version of stand-alone LR 6 about a month ago, I had to call and talk to the sales agent to know how. She was very nice and helpful, and I explained that I had tried the CC subscription in January and after 2 weeks decided that it was not for me and it canceled and got a refund of my money. She said no problem and that I could simply upgrade with a stand-alone version and I was not present on the CC subscription plan insofar as she could say. She took my credit card information and sent me the link to download.

    Now that I got a month I noticed by looking at the info system only under Version of Lightroom: CC2015.0.1 (1018573) it is said license: CC. That doesn't seem fair. I thought he'd say perpetual or something like that.

    I have also noticed that if I click on manage my account and it takes me to the connection, and then the page counts, he told the Plans and products, plan of creative photography of Cloud (one year).


    I'm starting to wonder if they still think I'm a CC map.

    Serialize Lightroom trial to activate like Lightroom 6 CC

  • Question about classes for the workshop held for OCP

    Im working on my OCP to complete in a few months. Quick question on the workshop class. Is there a test at the end of the week?
    Also how most people pay for these classes? They are quite steep and my company does not pay for this kind of thing for me. IM paying totally of my own pocket. Also why is the class in line of the same amount as the lead instructor class? His im not like in a room at some construction that Oracle has rent to use or something.

    If you ask if the certification test is offered at the end of the course, the answer is no. The certification test is on demand separately. Actually, in the past, some groups have asked for reviews delivered the last day of the formation of a class given internal by Oracle to their installation and the results have been disastrous. Candidates need time to assimilate the information, to work with the tools and continue their studies. You will schedule your exam at www.pearsonvue.com/oracle. Good luck with that!

    Kind regards
    Brandye Barrington
    Certification Forum Moderator

Maybe you are looking for

  • Problems with the new Macbook pro 15' maxed out

    Here's a quick post about my experience so far with the new macbook pro. I just got a brand new fully maxed out in spec macbook pro 15 inch 1 to SSD 16 GB RAM AMD R9 370 m GPU (set to automatic switching is not always) and a 2.8 to 4 GHz i7. I turned

  • IPod Classic does not recognize Itunes library after updating 12.4.1.6

    After (sigh, unconsciously and unintentionally) update my Itunes 12.4.1.6 Macbook Pro, my Ipod Classic is as it does not recognize the Itunes Macbook is the parent library. I made a few additions to the Macbook Itunes playlists, but my Ipod sync... a

  • All my Inbox messages are crumpled using yahoo

    When I login on the homepage of Yahoo, some overlap of script.When I sign in my mail messages from the Inboxseem to be on each other making it impossible to read

  • Satellite A100-153 is going on but then nothing happen

    Hello My Toshiba Satellite A100-153(PSAA9E-00D006GR) going on but then nothing!Nothing is displayed on the screen, no beeps, no flashing! I plugged with monitor external, thinking that the display was damaged but noway!I brought in an experienced fri

  • Impossible to install webcam on Qosmio G20

    I tried in vain to set up a webcam on my Qosmio G20 - Windows Media Center Edition machine. Logitech drivers are not supported under WMCE. Does anyone know cameras compatible or third party circumvention software?