04-12-2009 11:52 PM - edited 02-21-2020 04:12 PM
Hi, when the SA lifetime-negogation expires, and a new SA is formed so does it start from the very beginning i.e first IKE-phase1 (Main mode) and then Phase 2(quick mode) or is it just that phase 2 is re-negotiated?
What is the default behavior without using PFS?
04-13-2009 07:06 AM
The devices should only negotiate a new phase 2 key leaving the IKE phase intact, only when IKE goes down is when you will recreate both phases from scratch.
04-14-2009 08:34 AM
Thanks.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide