[Contents] [Prev] [Next] [Index] [Report an Error]

Understanding IPsec Security Associations (SAs)

A security association (SA) is a unidirectional agreement between the VPN participants regarding the methods and parameters to use in securing a communication channel. Full bidirectional communication requires at least two SAs, one for each direction.

Before You Begin

For background information, read

An SA groups together the following components for securing communications:

For outbound VPN traffic, the policy invokes the SA associated with the VPN tunnel. For inbound traffic, JUNOS software looks up the SA by using the following triplet:

In SRX-series services gateways, the IKE provides tunnel management for IPsec and authenticates end entities . The IKE performs a Diffie-Hellman key exchange to establish an IPsec tunnel between network devices.


[Contents] [Prev] [Next] [Index] [Report an Error]