08-21-2008 04:57 AM
Hi,
I have following query:
Is the lifetime parameter setting should be identical on both side firewall for both Phase-1 and Phase-2? or it can be different?
thnx
08-21-2008 05:05 AM
not must identical but better, When this lifetime expires, the IPsec peers renegotiate IKE phase 1
Many people choose to leave the IKE SA lifetime at the default value of 86400. It is worth noting, however, that the longer the lifetime, the less secure the SA is. The SA is less secure with a longer lifetime because with a longer lifetime an attacker has more time to collect encrypted traffic and subject it to cryptanalysis (attempt to recover the plaintext). However, a shorter IKE lifetime causes IPsec peers to have to renegotiate IKE more often
please, if helpful Rate
08-21-2008 11:08 PM
thanks for the detail but do the re-negotiation affects running ipsec-tunnel? that if tunnel disconnects?
thanks
08-21-2008 11:23 PM
no dose not effect the running one
please if helpful Rate
08-18-2013 12:55 PM
Hi Marwanshawi,
I was looking for same info which you answered here.
Regards
Mahesh
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide