cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4577
Views
0
Helpful
2
Replies

IPSEC SA Lifetime

mikedelafield
Level 1
Level 1

If one end of an IPSEC vpn has a lifetime set to 28800 secs and the other end 3600 secs, what effect will this have on the connection? And why?

The Vpn establishes and runs okay but periodically drops out. I presume this SA Lifetime mis-match is the cause, but was just curious as to why? As my understanding was that even though the lifetimes are different they agree on the lower value anyway?

Any thoughts?

2 Replies 2

ajagadee
Cisco Employee
Cisco Employee

Your understanding of the IPSEC SA Lifetime is correct. If you have 3600 and 28800 has the IPSEC Lifetime between two peers, the smaller value will be considered for the SA and in your case 3600. And a new SA is negotiated 30 seconds before the lifetime (3600) expires. This should keep your traffic flowing across the tunnel without any issues.

I hope it helps.

Regards,

Arul

mohammed.ayubi
Level 1
Level 1

is the SA life time same for both phase 1 and phase 2

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: