Updating IKE version
Hello,
I've just started working with Fortigate firewalls recently and have a question about updating policies. I would like to make a change to the IKE version, updating it to version 2. I'd just like confirmation that without modifying any other attributes of the proposals, if I tick off IKE version 2 under the Authentication menu within the web UI it will not disrupt the tunnel.
Essentially -- does modifying the authentication method force a re-negotiation of the security association? Also, is IKE version 2 backwards compatible with IKE version 1? I understand there are fewer packets during the initial negotiation but are the packets from IKEv2 understood by IKEv1 enough to form a tunnel/SA?
Thanks for any insight!
edit: It seems IKEv2 is not backwards compatible with IKEv1. I'm still wondering whether or not the change to the IKE version would cause a new SA negotiation right away or if it would wait for the lifetime of the tunnel to expire before negotiating another SA.
