Question

In: Computer Science

The IKE v1 protocol consists of two phases, i.e., Phase 1 and Phase 2. Describe the...

The IKE v1 protocol consists of two phases, i.e., Phase 1 and Phase 2. Describe the functions of each phase and two reasons why the protocol is separated into two phases.

Solutions

Expert Solution

In Computing , internet key exchange ( ike i.e. ike v1 or ike V2 depends on version) is the protocol used to set up Security association (SA) in the IPsec protocol suite. IKE builds upon the Oakley protocol and ISKAMP . The IKE is divided into two types :-

1.IKE V1 2. IKE V2.

Difference between them are :-.   

Theyhave different negotiation process. IKEv1 SA negotiation consists of two phases.

IKEv1 phase 1 negotiation aims to establish the IKE SA. This process supports the main mode and aggressive mode. Main mode uses six ISAKMP messages to establish the IKE SA, but aggressive mode uses only three. Therefore, aggressive mode is faster in IKE SA establishment. However, aggressive mode does not provide the Peer Identity Protection.
IKEv1 phase 2 negotiation aims to set up the IPSec SA for data transmission. This process uses the fast exchange mode (3 ISAKMP messages) to complete the negotiation.  Compared with IKEv1, IKEv2 simplifies the SA negotiation process. IKEv2 uses two exchanges (a total of 4 messages) to create an IKE SA and a pair of IPSec SAs. To create multiple pairs of IPSec SAs, only one additional exchange is needed for each additional pair of SAs.
Different authentication methods
IKEv2 supports EAP authentication. IKEv2 can use an AAA server to remotely authenticate mobile and PC users and assign private addresses to these users. IKEv1 does not provide this function and must use L2TP to assign private addresses.

Different supports for IKE SA integrity algorithms
IKE SA integrity algorithms are supported only in IKEv2.
Different implementations of DPD packet retransmission
The retry-interval parameter is supported only in IKEv1. If the NGFW sends a DPD packet but receives no reply within the specified retry-interval, the device includes a DPD failure event and retransmits a DPD packet. When the number of failure events reaches 5, both the IKE SA and IPSec SA are deleted. The IKE SA negotiation will be started again when the device has IPSec traffic to handle.

In IKEv2 mode, the retransmission interval increases from 1, 2, 4, 8, 16, 32 to 64 seconds. If no reply is received within eight consecutive transmissions, the peer is considered dead, and the IKE SA and IPSec SA will be deleted.
Different supports for manual lifetime settings
In IKEv2, the IKE SA soft lifetime is 9/10 of the IKE SA hard lifetime plus or minus a random value to reduce the likelihood that two endpoints initiate re-negotiation at the same time. Therefore, soft lifetime does not require manual settings in IKEv2.

Different supports for manual IPSec SA lifetime settings
In IKEv2, the IKE SA soft lifetime is 9/10 of the IKE SA hard lifetime plus or minus a random value to reduce the likelihood that two endpoints initiate re-negotiation at the same time. Therefore, soft lifetime does not require manual settings in IKEv2.


Related Solutions

The cleaning process of a certain industrial tank consists of 2 phases: • Phase 1: It...
The cleaning process of a certain industrial tank consists of 2 phases: • Phase 1: It begins by placing 2,000 L of water in the tank together with 100 kg of a certain chemical cleaner (soluble in water). • Phase 2: 40 L / min of water containing 2 kg of the cleaner per liter are poured into the tank. At the same time, the well mixed solution is pumped out of the tank at a rate of 45 L...
Name any two phases of mitosis and describe the cellular activities that occur during that phase.
Name any two phases of mitosis and describe the cellular activities that occur during that phase.
A forward lunge can be divided into 2 phases, the up phase and the down phase,...
A forward lunge can be divided into 2 phases, the up phase and the down phase, explain the type of contractions occurring in the knee joint (i.e. isometric, concentric, eccentic) during each of these phases. Then identify the movement and the prime (only 1) agonist muscle for the movement occurring in each of the following joints during the up phase: Pelvic girdle Hip joint Knee Ankle
1. Describe stationary phases and strong versus weak mobile phases for Reverse-phase chromatography, Hypophilic Imteraction chromatography,...
1. Describe stationary phases and strong versus weak mobile phases for Reverse-phase chromatography, Hypophilic Imteraction chromatography, and Ion Exchange chromatography. 2. Describe commonly used ion exchange materials and elution modes. 3. Describe “ion-exchange,” “ion-pair,” and “ion” chromatography. Please try to answer ALL questions, thank you!!!!
1. Identify starting/body position for the given movement 2. Describe the movement i.e. downward/upward phase a....
1. Identify starting/body position for the given movement 2. Describe the movement i.e. downward/upward phase a. Flexion/extension/Ab, Adduction etc b. Identify the plane and axis of the movement c. Describe ALL joints involved and their muscle action during each phase of the exercise (concentric, eccentric, isometric) d. Identify all the muscles involved with the movement and their respective contraction • Front squat • Pull-up (starting from the top) and Chin-up (from the bottom) • Conventional dead-lift • Arnold Press •...
Describe the 4 phases of demographic transition.  2 part question For each phase, compare crude birth...
Describe the 4 phases of demographic transition.  2 part question For each phase, compare crude birth rates (CBR) to crude death rates (CDR), and state whether the population is stable, growing, or declining in each.  Explain factors that contribute to changes in CBR and CDR between phases.
Please describe the phases of an action potential and what is going on in each phase....
Please describe the phases of an action potential and what is going on in each phase. What are the relative and absolute refractory periods?
What are th phases of glycolysis? Please describe the steps of each phase .
What are th phases of glycolysis? Please describe the steps of each phase .
1) Pick one of the phases of mitosis, and compare it to the similar phase in...
1) Pick one of the phases of mitosis, and compare it to the similar phase in meiosis I and meiosis II. For example, compare and contrast prophase of mitosis with prophase I and prophase II in meiosis. What is similar, and what is different? Use correct terminology (sister chromotids, sister chromosomes, centrosome, ect.) 2) What was something new that you learned from chapter 9? How would you explain this new information to someone interested in learning about inheritance? Did it...
1.Summarize the distinctions between the analysis phase and the design phase of the SDLC. 2. Describe...
1.Summarize the distinctions between the analysis phase and the design phase of the SDLC. 2. Describe the primary activities of the design phase of the SDLC. 3. Describe the three primary strategies that are available to obtain a new system. 4. What is involved with systems integration? When is it necessary? 5. Explain the distinctions between time and arrangements, fixed‐price, and value‐added outsourcing contracts. 6.What are the pros and cons of each?What is the purpose of a request for proposal...
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT