Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
patricktw
New Contributor

Updating IKE version

Hello,

 

I've just started working with Fortigate firewalls recently and have a question about updating policies.  I would like to make a change to the IKE version, updating it to version 2.  I'd just like confirmation that without modifying any other attributes of the proposals, if I tick off IKE version 2 under the Authentication menu within the web UI it will not disrupt the tunnel.

 

Essentially -- does modifying the authentication method force a re-negotiation of the security association? Also, is IKE version 2 backwards compatible with IKE version 1? I understand there are fewer packets during the initial negotiation but are the packets from IKEv2 understood by IKEv1 enough to form a tunnel/SA?

 

Thanks for any insight!

 

edit: It seems IKEv2 is not backwards compatible with IKEv1.  I'm still wondering whether or not the change to the IKE version would cause a new SA negotiation right away or if it would wait for the lifetime of the tunnel to expire before negotiating another SA.

0 REPLIES 0
Labels
Top Kudoed Authors