IKEv1

E522215

IKEv1 is the original version of the Internet Key Exchange protocol used to establish secure, authenticated communication channels for IPsec VPNs.

All labels observed (7)

How this entity was disambiguated

Statements (47)

Predicate Object
instanceOf Internet Key Exchange protocol
network security protocol
abbreviationFor Internet Key Exchange version 1
linked to: IKEv1
authenticationMethods digital signatures
pre-shared keys
public key encryption
category IPsec key management
definedBy Internet Engineering Task Force
introduced late 1990s
messageTransport UDP
negotiates encryption algorithms for IPsec
integrity algorithms for IPsec
key lifetimes
operatesOver UDP port 500
phaseStructure Phase 1 for IKE SA establishment
Phase 2 for IPsec SA negotiation
provides authentication
key establishment
security association negotiation
purpose establish secure communication channels for IPsec
perform key exchange for IPsec VPNs
provide mutual authentication between IPsec peers
relatedSpecification RFC 2407
RFC 2408
scope peer-to-peer VPN tunnels
remote access VPNs
site-to-site VPNs
standardizedIn RFC 2409
status obsoleted by IKEv2 in many deployments
successor IKEv2
supports NAT traversal via extensions
Perfect Forward Secrecy depending on configuration
aggressive mode
main mode
quick mode
usedWith IPsec
IPsec VPNs
uses Certificate payloads
Diffie–Hellman key exchange
Hash payloads
ISAKMP framework
Identification payloads
Key Exchange payloads
Oakley key determination protocol
Security Association payloads
vulnerabilities configuration complexity leading to misconfigurations
susceptible to certain denial-of-service attacks

How these facts were elicited

Referenced by (19)

Full triples — surface form annotated when it differs from this entity's canonical label.

IKEv2 obsoletes IKEv1
NAT-T relatedTo IKEv1
IKE fullName Internet Key Exchange
linked to: IKEv1
IKE basedOn ISAKMP
linked to: IKEv1
IKE Phase 2 partOf Internet Key Exchange
linked to: IKEv1
FFDHE groups usedInProtocol Internet Key Exchange
linked to: IKEv1
RFC 2401 relatedTo Internet Key Exchange
linked to: IKEv1
Authentication Header canBeNegotiatedBy Internet Key Exchange
linked to: IKEv1
IKEv1 abbreviationFor Internet Key Exchange version 1
linked to: IKEv1
RFC 5996 updatesSpecificationOf Internet Key Exchange
linked to: IKEv1
RFC 3947 relatedTo Internet Key Exchange
linked to: IKEv1
RFC 3947 relatedTo IKEv1
RFC 2409 title The Internet Key Exchange (IKE)
linked to: IKEv1
RFC 2409 protocolVersion IKEv1
RFC 2409 defines Quick Mode for IKE Phase 2
linked to: IKEv1
RFC 2409 relatedTo ISAKMP
linked to: IKEv1
SIGMA key exchange protocol usedAsBasisFor Internet Key Exchange version 1 (IKEv1)
linked to: IKEv1