[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Racing IKE SAs Revisited
On Tue, 1 Feb 2000, Kim Edwards wrote:
> context.... two peers simultaneously attempt to negotiate an IKE SA with
> each other
>
> After perusing the archives, it seems that implementations are
> supporting the simultaneous negotiation of 2 IKE SAs. Assume that PFS
> is not required and the two IKE SAs were successfully negotiated.
>
> Do we still keep both IKE SAs around until they expire?
> If so, can one peer use both IKE SAs to negotiate two different IPsec
> SAs?
>
Yes. You must keep both around. Which would you delete? What if the peer
deleted the other one?
I don't see a reason to not use either. If someone wants to formalize a way
to drop one of the two, I wouldn't have any objections. As it is, it's an
annoyance, but doesn't present any problems.
jan
--
Jan Vilhuber vilhuber@cisco.com
Cisco Systems, San Jose (408) 527-0847
References: