cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
365
Views
5
Helpful
2
Replies

L2L VPN Quick Question

johnnymac
Level 1
Level 1

Hi,

Just a quick question. I have a site to site VPN set up between two 515e's. I have recently rerouted the traffic that was previously traversing this link over a managed MPLS network. I was thinking i may keep the L2L VPN running as a failover option.

My question is would keeping the VPN link running use any significant overhead?

Regards

J Mack

2 Replies 2

haroon.shaikh
Level 1
Level 1

I dont think it should be of any overhead apart from normal keepalives. Also isakmp and ipsec will try to re-negotiate security associations after their lifetime is expired.

What you could do is set their security association lifetime to 1 day and they will re-negotiate them every 24 hours.

Thanks, thats really helpful.

Review Cisco Networking products for a $25 gift card