11-23-2011 08:19 AM
Hi All,
I have a question.
Is that a big problem to have different Phase 2 lifetimes configured on L2L VPN tunnels on both ends?
Like one end has P1 lifetime set to 86400 P2 lifetime set to 86400 and remote end has P1 set to 86400 and P2 set to 28800.
Thanks!
11-23-2011 08:39 AM
Its also part of Phase 1-2 Proposals mismatch will cause termination of tunnel.Should be same on both End.
Thanks
Ajay
11-23-2011 10:55 AM
I know that they will cause termination of the tunnel, because these timers are intended to do this.
The thing is that one end will terminate after 86400 and the other end will terminate after 28800.
So which end will force the lifetime timeout?
Depends on originator and responder? I.e. originator forces the timers on the remote end?
02-11-2012 02:17 AM
http://www.cisco.com/en/US/docs/ios/11_3/feature/guide/isakmp.html#wp6739
Then, if the lifetimes are not equal, the shorter lifetime will be selected. To restate this behavior: If the two peer's policies' lifetimes are not the same, the initiating peer's lifetime must be longer and the responding peer's lifetime must be shorter, and the shorter lifetime will be used.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: