ipsec November 2009 archive
Main Archive Page > Month Archives  > ipsec archives
ipsec: Re: [IPsec] How long does an IKEv1 session take to comple

Re: [IPsec] How long does an IKEv1 session take to complete?

From: Yoav Nir <ynir_at_nospam>
Date: Thu Nov 19 2009 - 05:49:15 GMT
To: "<hyla81420@mypacks.net> <hyla81420@mypacks.net>" <hyla81420@mypacks.net>


What Dan and Gregory said.

But assuming an unloaded gateway, with "normal" hardware (Any Intel, AMD or PowerPC processor from the last 10 years or a recent ARM), then even if you use relatively secure parameters (2048-bit DH group, 2048-bit RSA keys) the round trip time is going to dominate. The calculations themselves take less than 20 milliseconds.

So phase 1 should take about 3 round trips.

On Nov 18, 2009, at 8:31 AM, <hyla81420@mypacks.net> <hyla81420@mypacks.net> wrote:

> Greetings. Is there any data out there that quantifies how long a typical IKEv1 session (main mode and/or aggressive mode) take to complete?
>
> Hyla



IPsec mailing list
IPsec@ietf.org
https://www.ietf.org/mailman/listinfo/ipsec