IKE operation

IKE negotiates keys and establishes SAs for IPsec in two phases:

  • Phase 1—The two peers establish an ISAKMP SA, a secure, authenticated channel for communication.

  • Phase 2—Using the ISAKMP SA established in phase 1, the two peers negotiate to establish IPsec SAs.

  • Figure 87: IKE exchange process in main mode

    As shown in Figure 87, the main mode of IKE negotiation in phase 1 involves three pairs of messages: