Skip to main content
nnair
Staff
Staff
December 28, 2021

Technical Tip: Repeated authentication in IKEv2

  • December 28, 2021
  • 0 replies
  • 483 views
Description This article describes how to do Repeated authentication in IKEv2.
Scope  
Solution

This feature provides the option to control whether a unit requires its peer to re-authenticate or whether re-key is sufficient.

 

It does not influence the re-authentication or re-key behavior of the device itself, which is controlled by the peer (the default being to re-key).

 

This solution is in response to RFC 4478.

As described by the IETF, 'the purpose of this is to limit the time that security associations (SAs) can be used by a third party who has gained control of the IPsec peer'.

 

To configure IKE SA re-authentication:

 

# config vpn ipsec phase1-interfac
    edit p1
        set reauth [enable | disable]
    next
end

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!