RFC 7296: Internet Key Exchange Protocol Version 2 (IKEv2)
In plain English — editorial summary, not part of the RFC
This document describes version 2 of the Internet Key Exchange (IKE) protocol. IKE is a component of IPsec used for performing mutual authentication and establishing and maintaining Security Associations (SAs). This document obsoletes RFC 5996, and includes all of the errata for it. It advances IKEv2 to be an Internet Standard.
Document record
- Document ID
- RFC7296
- Published
- October 2014
- Authors
- C. Kaufman; P. Hoffman; Y. Nir; P. Eronen; T. Kivinen
- Status
- INTERNET STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 142
- Also known as
- STD79
- Obsoletes:
- RFC 5996
Topics
Standards lineage
This document is one revision in a chain of 7 RFCs, each formally replacing the one before it.
- RFC 2407 (1998)
- RFC 2408 (1998)
- RFC 2409 (1998)
- RFC 4306 (2005)
- RFC 4718 (2006)
- RFC 5996 (2010)
- RFC 7296 (2014)
Read the full history of Internet Key Exchange Protocol Version 2 (IKEv2) →
Referenced by
6 later RFCs formally update or obsolete part of this document.
- RFC 7427Signature Authentication in the Internet Key Exchange Version 2 (IKEv2)Current
January 2015
- RFC 7670Generic Raw Public-Key Support for IKEv2Current
January 2016
- RFC 8247Algorithm Implementation Requirements and Usage Guidance for the Internet Key Exchange Protocol Version 2 (IKEv2)Updated
September 2017
- RFC 8983Internet Key Exchange Protocol Version 2 (IKEv2) Notification Status Types for IPv4/IPv6 CoexistenceCurrent
February 2021
- RFC 9370Multiple Key Exchanges in the Internet Key Exchange Protocol Version 2 (IKEv2)Current
May 2023
- RFC 9827Renaming the Extended Sequence Numbers (ESN) Transform Type in the Internet Key Exchange Protocol Version 2 (IKEv2)Current
November 2025
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 4301Security Architecture for the Internet ProtocolUpdated
December 2005
- RFC 7018Auto-Discovery VPN Problem Statement and RequirementsCurrent
September 2013
- RFC 7634ChaCha20, Poly1305, and Their Use in the Internet Key Exchange Protocol (IKE) and IPsecCurrent
August 2015
- RFC 8221Cryptographic Algorithm Implementation Requirements and Usage Guidance for Encapsulating Security Payload (ESP) and Authentication Header (AH)Updated
October 2017
- RFC 8229TCP Encapsulation of IKE and IPsec PacketsObsoleted
August 2017
- RFC 8750Implicit Initialization Vector (IV) for Counter-Based Ciphers in Encapsulating Security Payload (ESP)Current
March 2020
- RFC 9329TCP Encapsulation of Internet Key Exchange Protocol (IKE) and IPsec PacketsCurrent
November 2022
- RFC 9395Deprecation of the Internet Key Exchange Version 1 (IKEv1) Protocol and Obsoleted AlgorithmsCurrent
April 2023
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?