Which of these is true regarding IKE Phase 2?
A.
The SAs used by IPsec are unidirectional, so a separate key exchange is required for each data flow.
B.
Either main or aggressive mode can be used to establish the SAs.
C.
Quick mode is used to establish the unidirectional IKE SA and the bidirectional IPsec SAs.
D.
XAUTH can be optionally used to reauthenticate the IPsec peers.
E.
The Diffie-Hellman protocol is used to exchange the public and private keys between the two IPsec peers.