Recently I was doing IPsec configuration in gns3 using encryption-aes , hash-sha & authentication-preshare key BUT what I'm confused is there is always an encryption key to encrypt the data, isn't it??? If it is then how does router with IPsec generates encryption key & if this key encrypts the data then what exactly 'aes' does??? Also how to know whether the key is symmetric key (private) or asymmetric key (public) ??? Can anyone plzz!!! explain this to me in an easiest way? thanx