[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Racing IKE SAs Revisited



On Tue, 1 Feb 2000, Kim Edwards wrote:
> context.... two peers simultaneously attempt to negotiate an IKE SA with
> each other
> 
> After perusing the archives, it seems that implementations are
> supporting the simultaneous negotiation of 2 IKE SAs.  Assume that PFS
> is not required and the two IKE SAs were successfully negotiated.
> 
> Do we still keep both IKE SAs around until they expire?
> If so, can one peer use both IKE SAs to negotiate two different IPsec
> SAs?
> 
Yes. You must keep both around. Which would you delete? What if the peer
deleted the other one?

I don't see a reason to not use either. If someone wants to formalize a way
to drop one of the two, I wouldn't have any objections. As it is, it's an
annoyance, but doesn't present any problems.

jan
 --
Jan Vilhuber                                            vilhuber@cisco.com
Cisco Systems, San Jose                                     (408) 527-0847



References: