Hello,
I've just started working with Fortigate firewalls recently and have a question about updating policies. I would like to make a change to the IKE version, updating it to version 2. I'd just like confirmation that without modifying any other attributes of the proposals, if I tick off IKE version 2 under the Authentication menu within the web UI it will not disrupt the tunnel.
Essentially -- does modifying the authentication method force a re-negotiation of the security association? Also, is IKE version 2 backwards compatible with IKE version 1? I understand there are fewer packets during the initial negotiation but are the packets from IKEv2 understood by IKEv1 enough to form a tunnel/SA?
Thanks for any insight!
edit: It seems IKEv2 is not backwards compatible with IKEv1. I'm still wondering whether or not the change to the IKE version would cause a new SA negotiation right away or if it would wait for the lifetime of the tunnel to expire before negotiating another SA.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.