[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

IKE v1 are multiple ISAKMP SA allowed



Hi,

I am implementing IKE v1 and i have few queries regarding ISAKMP SA
formation. Is it possible to have 2 ISAKMP SAs between the same two peers.

Consider the following case.

1. "A"  peer places request for ISAKMP SA negotiation.
2. Peer "B" also places request for ISAKMP SA negotiation at the same time.

So, at the same instance two Main Mode negotiations start. RFC 2409 says
that after Main mode negotiation the IPsec SAs can be exchanged by either
sides. So it sound logical to have only 1 main mode negotiation. So what do
we do if two Main Mode's start simultaneously?  If we have to discard one
Main Mode which one should we discard?

rfc 2409 doesnt say anything about multiple ISAKMP SA.

thanks and regards
Saket
PSS pune