RE: encryption

From: John Meggers (jcmegger@xxxxxxxxxxxxxxxxx)
Date: Sat Aug 12 2000 - 20:21:19 GMT-3


   
   That's what I did. I set up three routers in a chain, with a hub in
   between two of the routers, and a PC connected in running a packet
   analysis program. I could verify that when encryption was not active,
   the packets that were passing were clear text, and when the keys were
   exchanged and IPSec was active, the packets were encrypted. Not
   difficult to do, and I found it quite interesting as it was the first
   time I had worked with encryption.
   
   John C. Meggers, CCNP, CCDP, MCSE
   Sprint Enterprise Network Services
   Fairfax, Virginia
   Pager 1-888-314-7008
   jcmegger@sprintparanet.com
   
   -----Original Message-----
   From: nobody@groupstudy.com [mailto:nobody@groupstudy.com]On Behalf Of
   Robert LaGrasse
   Sent: Saturday, August 12, 2000 5:58 PM
   To: John Conzone; ccielab
   Subject: Re: encryption
   
   If you wanted to be absolutely sure, you could link the routers
   together on ethernet and use a pc based analyzer to look at the
   traffic...
   
   
   
   -----Original Message-----
   From: John Conzone <jkconzone@home.com>
   To: ccielab <ccielab@groupstudy.com>
   Date: Saturday, August 12, 2000 2:57 PM
   Subject: encryption
   
       I've set up a basic DES encryption between tow routers, and have
   checked the connection. It appears to be up.
   
   
   
   r2#sho crypto cisco connections
   Connection Table
   PE UPE Conn_id New_id Algorithm Time
   12.12.12.1 11.11.11.1 1 0 DES_56_CFB8 Mar 01 1993
   00:18:37
                   flags:TIME_KEYS ACL: 101
   
   
   
       I am able toping between the two routers. I've looked in the IOS
   but cannot find a way to make sure that my access list is working. In
   other words, I have a serial link beween r1 and r2. r1 is 10.10.10.1
   and r2 is 10.10.10.2. I've created a loopback on each. On r1,its
   11.11.11.1 and r2 its 12.12.12.1. My access list allows 11.11.11.1 to
   12.12.12.1 on r1, and the reverse on r2.
   
       How do I know that my pings (they work) are getting encrypted
   beside logging on the access-list? The log shows the access list
   getting hit, so am I to a assume its encrypted?



This archive was generated by hypermail 2.1.4 : Thu Jun 13 2002 - 08:24:24 GMT-3