Internet Key Exchange (IKE)
The protocol IPsec uses to authenticate peers and negotiate security associations, agreeing the algorithms and deriving shared keys through a Diffie-Hellman exchange.
Internet Key Exchange sets up the security associations that IPsec needs before it can protect any traffic. A security association records the algorithms, keys and lifetimes two peers have agreed for one direction of communication. IKE negotiates those parameters, uses a Diffie-Hellman exchange so that both sides derive shared secret keys without ever sending them, and authenticates each peer, commonly with pre-shared keys or with digital certificates issued under a public key infrastructure. The current version, IKEv2, is defined in RFC 7296; the original IKEv1 was defined in RFC 2409. IKE runs over UDP port 500, or 4500 when NAT traversal is in use.
IKEv1 works in two phases: the first builds a protected channel between the peers, and the second uses that channel to negotiate the security associations for the traffic itself. IKEv2 streamlines the exchange, adds support for Extensible Authentication Protocol methods, and handles peers behind address translation more cleanly. The keys IKE derives are then used by the symmetric encryption that protects the data, which is how IPsec combines asymmetric key agreement with fast bulk encryption.
Exam relevance: a scenario is likely to ask which part of IPsec negotiates keys and authenticates the endpoints. Candidates are expected to separate IKE, which manages keys, from AH and ESP, the protocols that protect the packets themselves.