Created on
05-12-2022
10:27 AM
Edited on
06-30-2025
12:41 AM
By
Jean-Philippe_P
Description | This article describes the behavior of FortiOS when SA rekey happens for phase1 and phase2 on FortiGate |
Scope | FortiGate. |
Solution |
What is a Security Association (SA). The concept of a 'Security Association' (SA) is fundamental to IPsec. A Security Association (SA) is a set of security policies and crypto keys used to protect the IKE SA or the IPsec SA.
What is an SPI (Security Parameters Index). The SPI is the identifier of an IPsec SA. It is a value that, together with the destination address and security protocol (ESP), uniquely
What are SA keys for IKEv1 and IKEv2. For IKEv1, IKE uses a single SA and a single key for both directions. For IKEv1, IPsec uses two SAs & two keys per direction. For IKEv2, IKE uses a single SA & two keys per direction. For IKEv2, IPsec uses two SAs & two keys per direction.
What is a SA (Security Association) rekey. IKE and ESP(IPsec) Security Associations have a finite lifetime. They use secret keys that should be used only for a limited amount of time and to protect a limited amount of data, which limits the lifetime of the entire Security Association. 'Re-keying' is the process of negotiating a new SA before hitting the lifetime expiry of the existing SA.
How does FortiOS handle the rekey of ADVPN shortcut tunnels. IKE SA (Phase1) rekey :
date=2021-06-27 time=13:35:59 id=6978575218893651968 itime="2021-06-27 13:36:00" euid=2 epid=2 dsteuid=2 dstepid=2 logver=700000066 logid=0101037124 type="event" subtype="vpn" level="error" action="negotiate" msg="IPsec phase 1 error" logdesc="IPsec phase 1 error" user="N/A" status="negotiate_error" remip=150.0.0.2 locip=90.0.0.2 remport=500 locport=500 outintf="port2" cookies="5107a9ab098aae35/0000000000000000" group="N/A" xauthuser="N/A" xauthgroup="N/A" vpntunnel="N/A" peer_notif="NOT-APPLICABLE" reason="peer SA proposal not match local policy" eventtime=1624826159949362758 tz="-0700" useralt="N/A" devid="FGVM0TTTTTTTTTTT" vd="root" dtime="2021-06-27 13:35:59" itime_t=1624826160 devname="Spoke1-SPLabs"
IPsec SA (Phase2) rekey: When Phase2 rekey happens in IKEv1 and IKEv2, the shortcut tunnel would not flush. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.