cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
444
Views
5
Helpful
1
Replies

Security Association lifetime question

philipbarker
Level 1
Level 1

Working through SNRS Greg Bastien.

I cannot work out what the Security lifetime is used for in Global config mode. I configured the lifetime parameters for both the IKE phase 1 and IPSEC 'crypto map' but then when I did :

'show crypto ipsec security-association'

found that the lifetime was set to 3600 seconds. I'm confused.

1 Reply 1

Global lifetime will be only used if the individual crypto map doesn't have a lifetime value configured. In your case since you have a lifetime value configured under the crypto map the router would use that value during security association negotiation with the peer.

HTH

Sundar