Chapter14 Internet Key Excha nge
Internet Key Exchange (IKE)
14-50
Cisco Router and Security Device Manager Version 2.2 Users Guide
OL-4015-08

Lifetime

This is the lifetime of the security association, in hours, minutes and seconds. The
default is one day, or 24:00:00.
IKE Pre-shared Keys
This window allows you to view, add, edit, and remove IKE pre-shared keys in the
routers configuration. A pre-shared key is exchanged with a remote peer during
IKE negotiation. Both peers must be configured with the same key.
Icon

Peer IP/Name

An IP address or name of a peer with whom this key is shared. I f an IP address is
supplied, it can specify all peers in a network or subnetwork, or just an individual
host. If a name is specified, then the key is shared by only the named peer.
Network Mask
The network mask specifies how much of the peer IP address is used for the
network address and how much is used for the host address. A network mask of
255.255.255.255 indicates that the peer IP address is an ad dress for a specific
host. A network mask containing zeros in the least significant bytes indicates that
the peer IP address is a network or subnet address. For example a network mask
of 255.255.248.0 indicates that the first 22 bits of the address are used for the
network address and that the last 10 bits are for the host part of the address.
Pre-Shared Key
The pre-shared key is not readable in SDM windows. If you need to examine the
pre shared key, go to View->Running Config. This will display the running
configuration. The key is contained in the crypto isakmp key comm and.
If a pre-shared key is read-only, the read-only icon appears in this
column. A pre-shared key will be marked as read-only if i t is
configured with the no-xauth CLI option