A network administrator is implementing GET VPN on Cisco IOS routers. The key server is configured with a policy that includes the `rekey` command. Which statement accurately describes the behavior of the rekey mechanism in GET VPN?
In GET VPN, the key server manages the GDOI protocol and distributes encryption keys to group members. The `rekey` command configures the key server to send rekey messages, which contain new keys or policies, to group members. This ensures that group members can update their keys without re-registering, maintaining secure communication.
Why this answer
GET VPN uses GDOI for group key management. The key server sends rekey messages to group members to update encryption keys and policies. This allows scalable key distribution without re-registration.
The rekey command configures the key server's rekey behavior, including algorithms and lifetimes. It directly impacts data plane keys, ensuring secure and efficient key rollover.
Exam trap
The trap here is thinking that rekey requires re-registration or is only for control plane, when it actually pushes new data plane keys to members.