IKE Phase 2 (Quick Mode)
¨
Negotiate parameters of IPsec SA
¨
Perfect Forward Secrecy (PFS) may be used
by initiator to request that a new DH secret
be generated over an encrypted channel
–
New nonces generated: N
i
` and N
r
`
–
New DH public values:
•
X
a
`=g
a
mod p
•
X
b
`=g
b
mod p
¨