During a simultaneous rekey in the pairwise-keys process, what is the maximum number of IPsec SAs temporarily created before converging onto the new SAs?
Choose an answer
Tap an option to check your answer.
Correct answer: 8.
Why this is the answer
During a simultaneous rekey in the pairwise-keys process, each vEdge router maintains two IPsec Security Associations (SAs) with every other vEdge router for data plane encryption: one for inbound traffic and one for outbound traffic. When a rekey occurs, both the old and new SAs must coexist temporarily to ensure seamless traffic flow during the transition. This means that for each peer, there will be two old SAs (inbound/outbound) and two new SAs (inbound/outbound) active simultaneously. Therefore, for a single peer-to-peer connection, there are 4 SAs temporarily active. If we consider the full duplex nature of the connection where both ends are rekeying simultaneously, the total number of SAs temporarily created before converging onto the new SAs is 8 (4 from router A's perspective to router B, and 4 from router B's perspective to router A).
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed