Some articles and Websites (Wikipedia and Cisco for instance) claim that unlike IKEv1, IKEv2 provides a support for Dead Peer Detection.However, unlike NAT traversal or DoS attacks for example, the official RFC 4306 did not mention how to address this problem. There is actually an official RFC 3706 "A Traffic-Based Method of Detecting Dead Internet Key Exchange (IKE) Peers" whose date IKEv2 IPsec Virtual Private Networks offers practical design examples for many common scenarios, addressing IPv4 and IPv6, servers, clients, NAT, pre-shared keys, resiliency, overhead, and more. If you’re a network engineer, architect, security specialist, or VPN administrator, you’ll find all the knowledge you need to protect your organization with IKEv2 and FlexVPN.
Continue reading