[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

FW: Negotiation for Ipsec SA



Hi,
   I am sorry if this has been discussed earlier. I have some doubt in the
negotiation of Ipsec SA.  When Ipsec decides to establish an Ipsec SA and
sends an SADB_ACQUIRE (PF_KEY Mesage) to the key management daemon.

1) For how much time should we wait for the SA to get negotiated. I feel
this is required.

2) If my first point is relevant, then should the time for the renegotiation
of the Ipsec SA, after the soft lifetime expires, be less then the
difference of the soft and hard seconds lifetime.


 Any comments on this are most welcome.


Awan Kumar Sharma



Follow-Ups: