Technical Tip: Repeated authentication in IKEv2
| Description | This article describes how to do Repeated authentication in IKEv2. |
| Scope | |
| Solution | This feature provides the option to control whether a unit requires its peer to re-authenticate or whether re-key is sufficient.
It does not influence the re-authentication or re-key behavior of the device itself, which is controlled by the peer (the default being to re-key).
This solution is in response to RFC 4478. As described by the IETF, 'the purpose of this is to limit the time that security associations (SAs) can be used by a third party who has gained control of the IPsec peer'.
To configure IKE SA re-authentication:
# config vpn ipsec phase1-interfac |
