[IPsec] Regarding IKEv2 REDIRECT problem (reference RFC 5685)

2014-05-02 Thread vijay kn
Hi, There is an issue in IKEv2 REDIRECT RFC 5685. In one scenario, the IKEv2 REDIRECT will not work indefinitely. Scenario: - Let's assume there are about 1000 clients connected to a IKEv2 REDIRECT enabled SeGW. None of the clients were IKEv2 redirect enabled at the time of establishing SA with

[IPsec] Simultaneous Child SA Creation tigger from both the side.

2014-05-02 Thread Syed Ajim Hussain
Hi All. Host A --Host B Assume Host-A & Host-B want to established IPSEC Tunnel, First they established one IKE SA and one IPSEC SA (Child SA). After that due to addition of a new IPSEC Policy(SPD), Both the sides triggered one more Child SA creation.