question on ipsec DH

From: ehtesham ali <conect2ehtesham_at_gmail.com>
Date: Tue, 8 Jun 2010 18:55:09 +0530

HI experts ,
i need to ask few questions about deffi hellman process of driving shared
secret key ,

1) R1---------------------R2 are trying to peer with each other using ipsec
, let say both use cisco as a password (pre-shared key ).
    since we already have a pre-shared key for encryption why do i need DH
process again to derive SHARED SECRET KEY ?

2) IS SHARED SECRET key derived from pre-shared key ?

3) for a site -to site and remote access tunnel what is default DH gr no .?

Thanks

Blogs and organic groups at http://www.ccie.net
Received on Tue Jun 08 2010 - 18:55:09 ART

This archive was generated by hypermail 2.2.0 : Sun Aug 01 2010 - 09:11:37 ART