Hello Kings, Thanks for the response. If i understand you correctly, what you are saying is after the IKE Phase 2 lifetime expires, along with the already existing IKE Phase 1 policy, another DH exchange takes place. This new DH exchange derives the session keys , which are again used in the IKE phase 2 exchange. Am i wrong in my understanding?
Cheers, TacACK
_______________________________________________ For more information regarding industry leading CCIE Lab training, please visit www.ipexpert.com Are you a CCNP or CCIE and looking for a job? Check out www.PlatinumPlacement.com
