Skip to main content
patricktw
New Member
October 13, 2015
Question

Updating IKE version

  • October 13, 2015
  • 0 replies
  • 2761 views

Hello,

 

I've just started working with Fortigate firewalls recently and have a question about updating policies.  I would like to make a change to the IKE version, updating it to version 2.  I'd just like confirmation that without modifying any other attributes of the proposals, if I tick off IKE version 2 under the Authentication menu within the web UI it will not disrupt the tunnel.

 

Essentially -- does modifying the authentication method force a re-negotiation of the security association? Also, is IKE version 2 backwards compatible with IKE version 1? I understand there are fewer packets during the initial negotiation but are the packets from IKEv2 understood by IKEv1 enough to form a tunnel/SA?

 

Thanks for any insight!

 

edit: It seems IKEv2 is not backwards compatible with IKEv1.  I'm still wondering whether or not the change to the IKE version would cause a new SA negotiation right away or if it would wait for the lifetime of the tunnel to expire before negotiating another SA.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!