cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
941
Views
0
Helpful
4
Replies

ISAKMP SA Lifetime question

Hi,

Is it possible to shorten the lifetime of ISAKMP SA's of dynamic remote VPN clients to 1 hr, but leave it alone (default is 24 hrs) for static VPN's? It seems this is a global setting that effects all VPN's equally, is this correct? Thanks, Mitchell

1 Accepted Solution

Accepted Solutions

crypto isakmp policy 1

lifetime 60

crypto isakmp policy 2

lifetime 86400*

*Since its the default you don't actually have to type it.

View solution in original post

4 Replies 4

pompeychimes
Level 4
Level 4

Yes, use different ISAKMP policies for each type of connection.

do these vpn's terminate on an asa or router?

The VPN's terminate on a 2851 ISR.

crypto isakmp policy 1

lifetime 60

crypto isakmp policy 2

lifetime 86400*

*Since its the default you don't actually have to type it.