In IKEv2, which exchange establishes the first CHILD_SA?
According to RFC 7296 (IKEv2) and Fortinet's official documentation, theIKE_SA_INIT exchangeis responsible for negotiating cryptographic parameters, performing the initial Diffie-Hellman exchange, and implementing the cookie challenge mechanism for DoS protection. When the responder suspects a DoS attack (such as mass requests by the same source), it includes a cookie in the IKE_SA_INIT response. The initiator must return the cookie in its next request to prove that it truly exists at the IP address it claims, thereby mitigating resource exhaustion attacks.
This two-step exchange ensures the responder only allocates resources after successful proof of address, aligning with best security practices. Fortinet documentation confirms that this process occurs strictly in the IKE_SA_INIT phase, not in subsequent IKE_Auth or CHILD_SA exchanges.
RFC 7296: IKEv2, Section 2.6, ''Denial of Service Protection''
Fortinet FortiOS VPN Handbook: IKEv2 Exchange Process and DoS Protection Mechanism
Deandrea
8 hours agoTesha
6 days agoTambra
11 days agoRene
16 days agoTegan
21 days agoIzetta
26 days agoMerilyn
1 month agoFelicitas
1 month agoEllsworth
1 month agoSamuel
2 months agoOren
2 months agoVeronica
2 months agoAnnamaria
2 months agoKenneth
2 months agoKirk
3 months agoMargart
3 months agoLorriane
3 months agoVerlene
3 months agoAyesha
2 months ago