Negotiates keys for IPsec tunnels. Site-to-site VPN connections in Azure rely on it together with IPsec, and Basic policy-based gateways support only the older IKEv1.
Also called Internet Key Exchange.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains IKE in context, with comparison tables and the common traps.
Terms in this definition
- IPsec
Internet Protocol Security is the set of protocols that negotiates and encrypts the tunnels used by VNet-to-VNet and site-to-site VPNs.
- S2S
Connects an entire on-premises office or datacentre to an Azure virtual network through an encrypted IPsec/IKE tunnel running between a local VPN device and an Azure VPN gateway.
- Basic
Low-cost Log Analytics table plan where ingestion is cheap but each query is charged per GB and runs at workspace scope. Full KQL and simple log search alerts are supported; standard log search alerts are not.
Related terms
- Custom IPsec/IKE policy
Set of algorithms for IKE Phase 1 and IPsec Phase 2, together with DH and PFS groups and SA lifetimes, applied to one connection rather than the gateway; each connection takes one policy, and every parameter has to be filled in.
- DH group
The Diffie-Hellman group chosen for key exchange during IKE Phase 1 (Main Mode) in a custom IPsec/IKE policy, such as DHGroup24 or DHGroup14.
- IKEDiagnosticLog
A VPN Gateway resource log giving detailed IKE and IPsec negotiation information, including SAs, proposals and PSK failures. Check it first when a tunnel fails to come up or repeatedly drops.
- IPsec/IKE
Together, Internet Protocol Security and Internet Key Exchange form the protocol suite that sets up and encrypts site-to-site and VNet-to-VNet VPN tunnels.
- New-AzIpsecPolicy
Cmdlet in Az.Network for defining a custom IPsec/IKE policy on a connection, covering IKE encryption and integrity, DH group, IPsec encryption and integrity, PFS group, and SA lifetime and size.
- SA lifetime
Rekeying threshold for an IPsec security association, given in seconds or KB of data and configured through a custom IPsec policy. Azure does not let you change the IKE Main Mode SA, which stays at 28,800 seconds.