[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Racing IKE SAs Revisited



context.... two peers simultaneously attempt to negotiate an IKE SA with
each other

After perusing the archives, it seems that implementations are
supporting the simultaneous negotiation of 2 IKE SAs.  Assume that PFS
is not required and the two IKE SAs were successfully negotiated.

Do we still keep both IKE SAs around until they expire?
If so, can one peer use both IKE SAs to negotiate two different IPsec
SAs?

-- 
Kim Edwards <kimed@nortelnetworks.com>
ILS Software Engineer, Nortel Networks
(613)765-8551





Follow-Ups: