Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Community Member

Lifetime parameter in VPN

Hi,

I have following query:

Is the lifetime parameter setting should be identical on both side firewall for both Phase-1 and Phase-2? or it can be different?

thnx

4 REPLIES

Re: Lifetime parameter in VPN

not must identical but better, When this lifetime expires, the IPsec peers renegotiate IKE phase 1

Many people choose to leave the IKE SA lifetime at the default value of 86400. It is worth noting, however, that the longer the lifetime, the less secure the SA is. The SA is less secure with a longer lifetime because with a longer lifetime an attacker has more time to collect encrypted traffic and subject it to cryptanalysis (attempt to recover the plaintext). However, a shorter IKE lifetime causes IPsec peers to have to renegotiate IKE more often

please, if helpful Rate

Community Member

Re: Lifetime parameter in VPN

thanks for the detail but do the re-negotiation affects running ipsec-tunnel? that if tunnel disconnects?

thanks

Re: Lifetime parameter in VPN

no dose not effect the running one

please if helpful Rate

Community Member

Re: Lifetime parameter in VPN

Hi Marwanshawi,

I was looking for same info which you answered here.

Regards

Mahesh

564
Views
0
Helpful
4
Replies
CreatePlease to create content