Correct Answer: To establish a secure, authenticated control channel (the ISAKMP/IKE SA) between the two peers, which is then used to negotiate the actual data-protecting IPsec SAs
Explanation: IKE Phase 1 establishes a secure, authenticated management channel used to negotiate Phase 2 IPsec SAs; it does not itself encrypt user data, assign addresses, resolve DNS, sync clocks, or establish routing adjacencies.
Correct Answer: To establish a secure, authenticated control channel (the ISAKMP/IKE SA) between the two peers, which is then used to negotiate the actual data-protecting IPsec SAs
Explanation: IKE Phase 1 establishes a secure, authenticated management channel used to negotiate Phase 2 IPsec SAs; it does not itself encrypt user data, assign addresses, resolve DNS, sync clocks, or establish routing adjacencies.