ipsec security association (SA) lifetime mismatch

Unanswered Question
Apr 15th, 2007

Can somebody tell me wht happens when the IPSEC SA lifetime mismatch happens in a VPN tunnel ? i tried creating a mismatch on two cisco routers but it worked without any problem. just wanted to confirm tht if theoritically it inflicts the IPSEC traffic in anyway ?

negotation happen when the lower lifetime expires , is it the case ?

i read tht the tunnel wont come up at all when there is a IPSEC mismatch but tht wasn't the case..

thanks

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
danail-petrov Tue, 04/17/2007 - 11:57

I believe that IKE/ISAKMP will negotiate the smallest lifetime value (seconds/bytes). U can easy check it by `show crypto isakmp sa detail` to see the lifetime value. Just execute `clear crypto isakmp` to ensure creating of fresh SA's .

Kind Regards,

Danail Petrov

Kamal Malhotra Tue, 04/17/2007 - 12:34

Hi,

This is how it goes, when there are 2 routers with different IPSEC SA lifetimes, then the tunnel would only come up if it is initiated from the end with higher lifetime configured. If you initiate the tunnel from the lower lifetime end, it should not come up. When the end with higher lifetime initiates the tunnel it is capable of setting its own lifetime to what is configured on the other end but not vice versa.

Once the tunnel is up as per the lower lifetime, when it renegotites, ideally it should not be successful. The reason is the IPSEC SA would still exist on the end with higer lifetime whereas the SAs are expired on the other end so you should see errors in the debugs.

This is the reason having the same lifetime is recommended.

HTH,

Please rate if it helps.

Regards,

Kamal

swapnendum Tue, 04/17/2007 - 22:16

Ok. Did a thorough testing on the lifetimes.

It doesn't matter from which end we initiate the traffic, both ends always negotiate the lower lifetime automatically. This applies for both IPSEC and ISAKMP lifetimes.

Did the testing on ver 12.3 (22).

Theoritically what Kamal says is correct but somehow it doesnt happen that way practically, strange.

Thanks everybody.

Actions

This Discussion