The invention provides a system and method for controlling the number of
Internet Protocol Security (IPsec) security associations per Internet Key
Exchange (IKE) security association for a single user. The limit on the
number of security association (SA) tunnels per key management protocol
SA may be stored in a server. A user equipment sends a request, to the
server, to set up a new SA. The server, upon receiving the request,
checks whether the limit on the number of SA tunnels per key management
protocol has been reached. The request is accepted when the limit has not
yet been reached.