Header
Home | Set as homepage | Add to favorites
  Search the Site     » Advanced Search
Sections
Syndication


Blogroll:

||||| ALL Cisco-Network ARTICLES |||||  
CCIE Journey,
The CCIE Journey,


Step 3—IKE Phase Two

Sep 25,2009 by alperen

image

Step 3�"IKE Phase Two

IKE Phase Two has only one mode, Quick mode, which occurs after IKE has established the secure tunnel in Phase One. In Quick mode, IKE

To negotiate the IPSec SAs, the sender forwards one or more transformsets, including transform combinations and related settings that represent the sender’s security requirements/preferences for the new IPSec session. The receiving peer compares these requirements to its own transform sets (requirements/preferences). If one matches, then the recipient returns that single transform set, indicating a mutually agreed on transform and algorithms for the IPSec session.

Quick mode is also used to renegotiate a new IPSec SA any time the IPSec SA lifetime expires. If PFS (next section) isn’t specified, Quick mode refreshes the key generation material used to create the shared secret keys derived from the DH exchange in Phase One.


307 times read

Related news

» Main Mode
by alperen posted on Sep 25,2009
» Step 2—IKE Phase One
by alperen posted on Sep 25,2009
» Step 1-3 Determine the IPSec (IKE Phase 2) Policies
by alperen posted on Sep 27,2009
» Step 3-1 Configure Transform Set Suites
by alperen posted on Sep 27,2009
» Diffie-Hellman Key Agreement (DH)
by alperen posted on Sep 25,2009
Did you enjoy this article?
(total 0 votes)

comment Comments (0 posted) 

More Top News
CCSP-Cisco Certified Security Professional
Most Popular
Most Commented
Featured Author