Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

IPSEC lifetime negotiations

Hi, when the SA lifetime-negogation expires, and a new SA is formed so does it start from the very beginning i.e first IKE-phase1 (Main mode) and then Phase 2(quick mode) or is it just that phase 2 is re-negotiated?

What is the default behavior without using PFS?

2 REPLIES

Re: IPSEC lifetime negotiations

The devices should only negotiate a new phase 2 key leaving the IKE phase intact, only when IKE goes down is when you will recreate both phases from scratch.

New Member

Re: IPSEC lifetime negotiations

Thanks.

187
Views
0
Helpful
2
Replies