A Quick Crash Detection Method for the Internet Key Exchange Protocol (IKE), June 2011
- File formats:
- PROPOSED STANDARD
- Y. Nir, Ed.
- ipsecme (sec)
Discuss this RFC: Send questions or comments to firstname.lastname@example.org
This document describes an extension to the Internet Key Exchange Protocol version 2 (IKEv2) that allows for faster detection of Security Association (SA) desynchronization using a saved token.
When an IPsec tunnel between two IKEv2 peers is disconnected due to a restart of one peer, it can take as much as several minutes for the other peer to discover that the reboot has occurred, thus delaying recovery. In this text, we propose an extension to the protocol that allows for recovery immediately following the restart. [STANDARDS-TRACK]
For the definition of Status, see RFC 2026.
For the definition of Stream, see RFC 8729.