IKEv2/IPsec SA counter synchronization

Document Type Expired Internet-Draft (individual)
Last updated 2010-07-29
Stream (None)
Intended RFC status (None)
Expired & archived
plain text pdf html bibtex
Stream Stream state (No stream defined)
Consensus Boilerplate Unknown
RFC Editor Note (None)
IESG IESG state Expired
Telechat date
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft can be found at


IKEv2 and IPsec protocols are widely used for deploying VPN. In order to make such VPN highly available and failure-prone, these VPNs are implemented as IKEv2/IPsec Highly Available (HA) cluster. But there are many issues in IKEv2/IPsec HA cluster. The draft "IPsec Cluster Problem Statement" enumerates all the issues encountered in IKEv2/IPsec HA cluster environment. This draft proposes an extension to IKEv2 protocol to solve main issues of "IPsec Cluster Problem Statement" in Hot Standby cluster and gives implementation advice for others. The main issues to be solved are: o IKE Message Id synchronization : This is done by obtaining the message Id values from the peer and updating the values at the newly active cluster member after the failover. o IPsec SA Counter synchronization : This is done by sending incremented the values of replay counters by the newly active cluster member to the peer as expected replay counter value.


Kalyani Garigipati (kagarigi@cisco.com)

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)