RFC 7791: Cloning the IKE Security Association in the Internet Key Exchange Protocol Version 2 (IKEv2)
In plain English — editorial summary, not part of the RFC
This document considers a VPN end user establishing an IPsec Security Association (SA) with a Security Gateway using the Internet Key Exchange Protocol version 2 (IKEv2), where at least one of the peers has multiple interfaces or where Security Gateway is a cluster with each node having its own IP address. The protocol described allows a peer to clone an IKEv2 SA, where an additional SA is derived from an existing one. The newly created IKE SA is set without the IKEv2 authentication exchange. This IKE SA can later be assigned to another interface or moved to another cluster node.
Document record
- Document ID
- RFC7791
- Published
- March 2016
- Authors
- D. Migault; V. Smyslov
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- —
- Pages
- 14
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 6790The Use of Entropy Labels in MPLS ForwardingUpdated
November 2012
- RFC 6419Current Practices for Multiple-Interface HostsCurrent
November 2011
- RFC 6418Multiple Interfaces and Provisioning Domains Problem StatementCurrent
November 2011
- RFC 6311Protocol Support for High Availability of IKEv2/IPsecCurrent
July 2011
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?