Main mode
Under ordinary conditions, establishing the ISAKMP SA requires several packets to be sent and received:
- The first two messages determine communications policy.
- The next two messages exchange Diffie-Hellman public data.
- The last two messages authenticate the Diffie-Hellman exchange.
This is the normal method of establishing a successful Phase 1 connection, and it is called main mode. This method provides the most security and privacy, because authentication information is not exchanged until a full Diffie-Hellman exchange has been negotiated and encryption has been enabled. The vRouter supports main mode.