RFC 4306: Internet Key Exchange (IKEv2) Protocol
This RFC has been replaced. Do not implement against it for new work — it was formally obsoleted by RFC 5996.
Current document in this lineage: RFC 7296 — Internet Key Exchange Protocol Version 2 (IKEv2)
In plain English — editorial summary, not part of the RFC
This document describes version 2 of the Internet Key Exchange (IKE) protocol. IKE is a component of IPsec used for performing mutual authentication and establishing and maintaining security associations (SAs). This version of the IKE specification combines the contents of what were previously separate documents, including Internet Security Association and Key Management Protocol (ISAKMP, RFC 2408), IKE (RFC 2409), the Internet Domain of Interpretation (DOI, RFC 2407), Network Address Translation (NAT) Traversal, Legacy authentication, and remote address acquisition. Version 2 of IKE does not interoperate with version 1, but it has enough of the header format in common that both versions can unambiguously run over the same UDP port. [STANDARDS-TRACK]
Document record
- Document ID
- RFC4306
- Published
- December 2005
- Authors
- C. Kaufman
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 99
- Also known as
- —
Topics
Standards lineage
This document is one revision in a chain of 7 RFCs, each formally replacing the one before it.
- RFC 2407 (1998)
- RFC 2408 (1998)
- RFC 2409 (1998)
- RFC 4306 (2005)
- RFC 4718 (2006)
- RFC 5996 (2010)
- RFC 7296 (2014) ✓
Read the full history of Internet Key Exchange Protocol Version 2 (IKEv2) →
Referenced by
2 later RFCs formally update or obsolete part of this document.
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 4303IP Encapsulating Security Payload (ESP)Current
December 2005
- RFC 4302IP Authentication HeaderCurrent
December 2005
- RFC 4305Cryptographic Algorithm Implementation Requirements for Encapsulating Security Payload (ESP) and Authentication Header (AH)Obsoleted
December 2005
- RFC 1828IP Authentication using Keyed MD5Current
August 1995
- RFC 4109Algorithms for Internet Key Exchange version 1 (IKEv1)Current
May 2005
- RFC 4835Cryptographic Algorithm Implementation Requirements for Encapsulating Security Payload (ESP) and Authentication Header (AH)Obsoleted
April 2007
- RFC 6518Keying and Authentication for Routing Protocols (KARP) Design GuidelinesCurrent
February 2012
- RFC 4301Security Architecture for the Internet ProtocolUpdated
December 2005
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?