IKE Phase 2

E184262

IKE Phase 2 is the stage of the IPsec key exchange process where security associations are negotiated and keys are established for protecting actual data traffic between peers.

All labels observed (1)

Label Occurrences
IKE Phase 2 canonical 2

How this entity was disambiguated

Statements (45)

Predicate Object
instanceOf IPsec key exchange phase ⓘ
protocol phase ⓘ
alsoKnownAs Quick Mode ⓘ
canRekey IPsec SAs ⓘ
canUse transport mode ⓘ
tunnel mode ⓘ
definedIn IKEv1 specifications ⓘ
IPsec architecture ⓘ
dependsOn Phase 1 cryptographic parameters for protection of negotiation ⓘ
establishes IPsec Security Associations ⓘ
child SAs ⓘ
exchanges Quick Mode messages ⓘ
follows IKE Phase 1 ⓘ
lifetime typically shorter than IKE Phase 1 lifetime ⓘ
messageCount three-message exchange in IKEv1 Quick Mode ⓘ
negotiates IPsec lifetime ⓘ
IPsec mode ⓘ
Perfect Forward Secrecy usage ⓘ
encryption algorithms for IPsec SAs ⓘ
integrity algorithms for IPsec SAs ⓘ
proxy identities ⓘ
traffic selectors ⓘ
notScope IKE SA establishment ⓘ
peer authentication ⓘ
occursBetween IPsec peers ⓘ
partOf IPsec key management ⓘ
Internet Key Exchange ⓘ
linked to: IKEv1
produces AH SAs ⓘ
ESP SAs ⓘ
protects tunneled VPN traffic ⓘ
unicast data traffic ⓘ
purpose establish keys for protecting user data ⓘ
negotiate IPsec protection parameters for data traffic ⓘ
relatedTo IKEv2 Child SA creation ⓘ
requires successful IKE Phase 1 ⓘ
runsOver IKE Phase 1 SA ⓘ
scope data-plane protection parameters ⓘ
securityProperty can provide Perfect Forward Secrecy ⓘ
standardizedBy IETF ⓘ
usedIn host-to-host IPsec deployments ⓘ
remote-access VPNs ⓘ
site-to-site VPNs ⓘ
uses Diffie–Hellman for PFS when configured ⓘ
ISAKMP SA ⓘ
Phase 1 encryption and integrity to protect its messages ⓘ

How these facts were elicited

Referenced by (2)

Full triples — surface form annotated when it differs from this entity's canonical label.

RFC 3526 → appliesTo → IKE Phase 2 ⓘ
RFC 2409 → specifies → IKE Phase 2 ⓘ