IKE is the control-plane protocol that authenticates IPsec peers and negotiates the parameters needed to establish secure associations. Those parameters include acceptable cryptographic algorithms, authentication methods, Diffie-Hellman groups, lifetimes, and keying material. Cisco explains that IKE establishes the secure VPN relationship and creates security associations for IPsec; therefore, negotiating tunnel parameters is the best answer. IKE does not itself filter packets, which is performed by access-control or firewall policy. It also does not manage application data transfer. After negotiation completes, IPsec mechanisms such as Encapsulating Security Payload protect user packets according to the negotiated security associations. Thus, option D incorrectly assigns data-plane packet encryption directly to IKE rather than to IPsec. Cisco’s IKE documentation confirms these functions.
================
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit