Quantcast
Viewing all articles
Browse latest Browse all 17645

Re: IPsec Phase II SA active but not Phase I SA

Hello,

 

IMO it is possible in scenarios where the phase 1 SA has timed out but the phase 2 SA are still active and running. In such situations the phase 1 negotiation will not start untill DPD or phase 2 rekey needs it.

 

The following KB document explain more about how phase 1 and phase 2 negotiation take place during rekey/timeout and thius explains the situation where the phase 1 is not present but phase 2 is still seen.

http://kb.juniper.net/InfoCenter/index?page=content&id=KB28636&actp=search 

 

Please let me know if you have any queries in understanding anything from the above article.

 

Thanks,
Pulkit Bhandari
Please mark my response as Solution Accepted if it Helps, Kudos are Appreciated too. Image may be NSFW.
Clik here to view.
Smiley Happy


Viewing all articles
Browse latest Browse all 17645

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>