For VPN connections that use L2TP over IPSec is there any stronger encryption that can be used (or required) other than DES / 3DES encryption?

    Requires Free Membership to View

JD,
There are new encryption algorithms being developed, but 3DES is probably sufficient for you now, especially if you change the session keys regularly (e.g., every few hours or so).

The more critical component of security is authentication. It's surprising how many folks will encrypt using 3DES but still use shared secrets or PAP for authentication. I recommend either secure tokens or digital certificates. Authentication and encryption go hand-in-hand to provide the best security.

This was first published in February 2003

Join the conversationComment

Share
Comments

    Results

    Contribute to the conversation

    All fields are required. Comments will appear at the bottom of the article.