Skip to main content
IBM 
ShopSupportDownloads
IBM HomeProductsConsultingIndustriesNewsAbout IBM
IBM : developerWorks : Security : Education - online courses
Virtual private networks, Part 2
Download tutorial zip fileView letter-sized PDF fileView A4-sized PDF fileE-mail this tutorial to a friend
Main menuSection menuGive feedback on this tutorialPreviousNext
4. Key exchange
  


Some useful optimizations I page 10 of 11


In Quick Mode negotiating a range of SAs will speed up the "re-keying." When one peer feels it is time to change SAs they simply use the next one within the stated range. A range of SAs can be established by negotiating multiple SAs (identical attributes, different SPIs) with one Quick Mode.

Establishing SAs with peers before they are needed ensures there will be no delays due to key management before initial data transmission. Multiple negotiations are performed, and those not immediately used are cached. To make things even faster, if ISAKMP is alerted that a SA will soon be needed (say, to replace an expiring SA) then it can establish the new SA before that new SA is needed.


Main menuSection menuGive feedback on this tutorialPreviousNext
PrivacyLegalContact