Sankar, The question of using TCP vs. UDP as a basis for IKE was discussed and resolved long ago on the IPsec list. I will leave it to other more deeply involved in IKE to answer that question. I thought you were asking a question re keepalive use for individual SAs. Steve