Method and device for synchronizing security association (SA) between equipment
暂无分享,去创建一个
The invention discloses a method and device for synchronizing security association (SA) between equipment. The method comprises the following steps of: receiving identification information of opposite-terminal IPsec (internet protocol security) SA peer equipment transmitted from the opposite-terminal IPsec SA peer equipment in an IKE (Internet Key Exchange) SA negotiation process between IPsec SA peer equipment and the opposite-terminal IPsec SA peer equipment; deleting the IKE SA and the IPsec SA, inquired according to the identification information, on the IPsec SA equipment; and establishing the IPsec SA between the IPsec SA peer equipment and the opposite-terminal IPsec SA peer equipment by virtue of taking the identification information as an index. The method and the device can be used for solving the problem of data loss between the equipment, saving CPU (Central Processing Unit) resources and improving the utilization rate of the CPU resources; and as the IPsec SA peer equipment is informed of deleting the useless SA by an IKE SA negotiation message in the IKE SA negotiation process, the burden from extra message interaction between the equipment is not added, and bandwidth resources are saved.