Created on 05-12-2022 10:27 AM Edited on 05-12-2022 10:28 AM By Anonymous
Description | This article describes the behaviour of FortiOS when SA rekey happens for phase1 and phase2 on FortiGate |
Scope | FortiGate. |
Solution |
What is a Security Association (SA)? The concept of a 'Security Association' (SA) is fundamental to IPsec. A Security Association (SA) is a set of security policies and crypto keys used to protect the IKE SA or the IPsec SA.
-The same IKE SA is used to protect incoming and outgoing traffic. -Two distinct IPsec SA (one per direction) are used for incoming and outgoing traffic. -SA includes the specific security protections, cryptographic algorithms, and secret keys to be applied, as well as the specific types of traffic to be protected.
What is an SPI (Security Parameters Index)? The SPI is the identifier of an IPsec SA. It is a value that, together with the destination address and security protocol (ESP), uniquely
What are SA keys for IKEv1 and IKEv2? For IKEv1, IKE uses single SA and single keys for both directions. For IKEv1, IPsec uses two SAs & two keys per direction For IKEv2, IKE uses single SA & two keys per direction For IKEv2, IPsec uses two SAs & two keys per direction
What is a SA (Security Association) rekey? IKE and ESP(IPsec) Security Associations use secret keys that should be used only for a limited amount of time and to protect a limited
How does FortiOS handle the rekey of ADVPN shortcut tunnels?
IKE SA (Phase1) rekey :
date=2021-06-27 time=13:35:59 id=6978575218893651968 itime="2021-06-27 13:36:00" euid=2 epid=2 dsteuid=2 dstepid=2 logver=700000066 logid=0101037124 type="event" subtype="vpn" level="error" action="negotiate" msg="IPsec phase 1 error" logdesc="IPsec phase 1 error" user="N/A" status="negotiate_error" remip=150.0.0.2 locip=90.0.0.2 remport=500 locport=500 outintf="port2" cookies="5107a9ab098aae35/0000000000000000" group="N/A" xauthuser="N/A" xauthgroup="N/A" vpntunnel="N/A" peer_notif="NOT-APPLICABLE" reason="peer SA proposal not match local policy" eventtime=1624826159949362758 tz="-0700" useralt="N/A" devid="FGVM0TTTTTTTTTTT" vd="root" dtime="2021-06-27 13:35:59" itime_t=1624826160 devname="Spoke1-SPLabs"
IPsec SA (Phase2) rekey:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.