Hi All,
I have find the following info on Microsoft web site:
"SA lifetimes i IKE
The main mode SA is cached to allow multiple quick mode SA negotiations (unless master key PFS is enabled). When a key lifetime is reached for the master or session key, the SA is renegotiated. In addition, the key is refreshed or regenerated.
When the default time-out period elapses for the main mode SA, or the master or session key lifetime is reached, a delete message is sent to the responder. The IKE delete message tells the responder to expire the main mode SA. This prevents additional new quick mode SAs from being created from the expired main mode SA. IKE does not expire the quick mode SA, because only the IPSec driver contains the number of seconds or bytes that have passed to reach the key lifetime."
Just to be clear does it mean that when the main mode expire only the SA for the MAIN mode need to be regenerated or both Main Mode+Quick Mode need renegotiation?
Thanks
Matteo