lOur
drafts propose an extension to IKEv2 that
securely signal to its peer that it
has lost state.
lWhen
a gateway receives an IKE message with an unknown
IKE SPI, it proceeds with an augmented INVALID_IKE_SPI
exchange
lUpon
completion, the side with the remaining SA's has
sufficient proof that its peer has lost state.