RFC 7791 · PROPOSED STANDARD · 2016

Cloning the IKE Security Association in the Internet Key Exchange Protocol Version 2

Overview

RFC 7791, “Cloning the IKE Security Association in the Internet Key Exchange Protocol Version 2”, is a Proposed Standard document published in March 2016 by D. Migault, V. Smyslov. The canonical text is published by the RFC Editor.

Abstract

This document considers a VPN end user establishing an IPsec Security Association (SA) with a Security Gateway using the Internet Key Exchange Protocol version 2 (IKEv2), where at least one of the peers has multiple interfaces or where Security Gateway is a cluster with each node having its own IP address.

The protocol described allows a peer to clone an IKEv2 SA, where an additional SA is derived from an existing one. The newly created IKE SA is set without the IKEv2 authentication exchange. This IKE SA can later be assigned to another interface or moved to another cluster node.

Abstract as published in the RFC, via rfc-editor.org.

What “Proposed Standard” means

An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.

Read this RFC

The canonical text of RFC 7791 is hosted at rfc-editor.org. Available in TXT,HTML.

Other RFCs from 2016

Who Is Online

In total there are 47 users online: 0 registered, 39 guests and 8 bots.

Most users ever online was 1,226 on 13 Jun 2026, 3:56 am.

Bots: AhrefsBot Applebot Facebook Googlebot Other Bot Other Crawler Other Spider SemrushBot

Users active in the past 15 minutes. Total registered members: 354