cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
920
Views
0
Helpful
1
Replies

changing the IPSEC sa lifetime

lgontarsk
Level 1
Level 1

Hi,

If I use the

crypto IPSEC security-association lifetime command, doesn't that hold for all clients? I'm trying to change it only for one IPSEC sa and i don't want to interrupt any other already existing VPN clients.

is there a way to set it for just one client?

Thanks!

Lisa G

1 Accepted Solution

Accepted Solutions

srue
Level 7
Level 7

you can change it under the crypto map configuration for each individual connection. since you didn't state what device your vpn's are terminated on though, i can't give you a specific example.

the command you gave is global, for which there exists a default lifetime already. 'local' lifetimes for individual crypto maps override this value.

also, if two peers differ in their lifetimes during negotiation, they are 'supposed' to choose the smallest value, but still connect.

View solution in original post

1 Reply 1

srue
Level 7
Level 7

you can change it under the crypto map configuration for each individual connection. since you didn't state what device your vpn's are terminated on though, i can't give you a specific example.

the command you gave is global, for which there exists a default lifetime already. 'local' lifetimes for individual crypto maps override this value.

also, if two peers differ in their lifetimes during negotiation, they are 'supposed' to choose the smallest value, but still connect.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: