Main Mode IKE expiring , what's next?

Aug 20, 2005 0 Replies

Hi All,



I have find the following info on Microsoft web site:



"SA lifetimes i IKE



The main mode SA is cached to allow multiple quick mode SA negotiations (unless master key PFS is enabled). When a key lifetime is reached for the master or session key, the SA is renegotiated. In addition, the key is refreshed or regenerated.



When the default time-out period elapses for the main mode SA, or the master or session key lifetime is reached, a delete message is sent to the responder. The IKE delete message tells the responder to expire the main mode SA. This prevents additional new quick mode SAs from being created from the expired main mode SA. IKE does not expire the quick mode SA, because only the IPSec driver contains the number of seconds or bytes that have passed to reach the key lifetime."



Just to be clear does it mean that when the main mode expire only the SA for the MAIN mode need to be regenerated or both Main Mode+Quick Mode need renegotiation?



Thanks



Matteo


Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required