Mechanisms to Ensure Continuity of Service for IPsec/IKEv2 Based Communications
Daniel Palomares, Maryline Laurent · 2011
Abstract – Today, the internet is crucial in almost any possible area, idea or project. The exponential growth of such network (particularly the growth of mobile internet in short term) makes the security a very important issue to manage. The IPsec suite is presented as one of the most used and deployed protocols on the net, commonly implemented as VPN 1, accompanied by a mechanism called IKE 2 (IKEv2 stands for version two). It ensures maintaining a shared state between the connected entities in a dynamic way, called Security Associations (SAs). IPsec and IKE protocols both maintain what is called an IPsec/IKEv2 security context. When implementing IPsec/IKEv2 clusters, the main goal is to maintain the same security level even if the connection is moved from one gateway to another with no need for starting a new IPsec/IKEv2 negotiation. This would save ISP’s 3 costs and would assure high availability. In