Security Internetworking Experts


Post New Topic  Post A Reply
my profile | register | search | faq | forum home
  next oldest topic   next newest topic
» Security Internetworking Experts   » Security   » CCIE Security Written Forum   » Why 2 different transform sets for IPSec

UBBFriend: Email this page to someone!    
Author Topic: Why 2 different transform sets for IPSec
murali_uda
Jr Member

Member # 32401

Rate Member
posted June 16, 2012 01:40 AM      Profile for murali_uda     Send New Private Message      Edit/Delete Post  Reply With Quote 
Hi all,

I have this doubt from long time , I dont know why we have to negotiate policies again for data in IKE phase 2 ?

As DH keys are exchanged and secure management connection established why cant we use the same sym encryption key negotiated in the phase 1 for data encryption ...why we are using the sym key exchanged in phase 1 to again encrypt the messages to negotiate polices and the use that sym key for data?

Thanks for your time,
Murali.

Posts: 12 | From: bangalore | Registered: May 2012  |  IP: Logged


All times are Eastern Time  
Post New Topic  Post A Reply Close Topic    Move Topic    Delete Topic next oldest topic   next newest topic
Printer-friendly view of this topic
Hop To:


Contact Us | Security Internetworking Experts