<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ask about Associaton Lifetime in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ask-about-associaton-lifetime/m-p/4079400#M1069849</link>
    <description>&lt;P&gt;Hi Sheraz,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your response,&lt;/P&gt;&lt;P&gt;What kind config do you want? or you just write the command what do you want here?&lt;/P&gt;&lt;P&gt;this just happen we still investigate and what happen when i set a lifetime association longer ? is there any problem on security if i changed longer?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
    <pubDate>Tue, 05 May 2020 01:05:01 GMT</pubDate>
    <dc:creator>danielbusisa1410</dc:creator>
    <dc:date>2020-05-05T01:05:01Z</dc:date>
    <item>
      <title>Ask about Associaton Lifetime</title>
      <link>https://community.cisco.com/t5/network-security/ask-about-associaton-lifetime/m-p/4078846#M1069817</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have some question about the lifetime association, I have work with AWS VPN L2L and our tunnel is already up.&lt;/P&gt;&lt;P&gt;but every 1 hour the tunnel state is down, is this because i set the lifetime association 3600 ? and what if i changed the lifetime association to be longer is that possible or not? there is any problem after i changed it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your respond is needed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2020 10:09:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ask-about-associaton-lifetime/m-p/4078846#M1069817</guid>
      <dc:creator>danielbusisa1410</dc:creator>
      <dc:date>2020-05-04T10:09:23Z</dc:date>
    </item>
    <item>
      <title>Re: Ask about Associaton Lifetime</title>
      <link>https://community.cisco.com/t5/network-security/ask-about-associaton-lifetime/m-p/4078858#M1069819</link>
      <description>&lt;P&gt;in version ikev1 if the time values of phase 1 are different on both routers/firewalls than the lower value always have a win. &amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;SPAN style="display: inline !important; float: none; background-color: #ffffff; color: #58585b; font-family: CiscoSans,Arial,sans-serif; font-size: 16px; font-style: normal; font-variant: normal; font-weight: 300; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"&gt;lifetime association, &lt;/SPAN&gt;This is the lifetime of the keys that the tunnel uses to encrypt data.&lt;BR /&gt;The time and data limits are there to protect the integrity of the keys used to encrypt you data. &lt;BR /&gt;The data limit is there so that no part of the key is used twice. &lt;BR /&gt;I just leave mine set as default.&lt;BR /&gt;8 Hours&lt;BR /&gt;460800 KBytes&lt;BR /&gt;When these timers run out the tunnel negotiates a new key. If you have activity through the tunnels you shouldn't even notice when these timers expire.&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2020 10:45:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ask-about-associaton-lifetime/m-p/4078858#M1069819</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2020-05-04T10:45:11Z</dc:date>
    </item>
    <item>
      <title>Re: Ask about Associaton Lifetime</title>
      <link>https://community.cisco.com/t5/network-security/ask-about-associaton-lifetime/m-p/4078862#M1069820</link>
      <description>&lt;P&gt;Hi Sheraz,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I still don't get it, is there any issue if i change the lifetime association? and when i set it 3600 second, it means every 1 hour the vpn generated a new key and make some traffic state down for a while?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your attention&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2020 10:45:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ask-about-associaton-lifetime/m-p/4078862#M1069820</guid>
      <dc:creator>danielbusisa1410</dc:creator>
      <dc:date>2020-05-04T10:45:32Z</dc:date>
    </item>
    <item>
      <title>Re: Ask about Associaton Lifetime</title>
      <link>https://community.cisco.com/t5/network-security/ask-about-associaton-lifetime/m-p/4078875#M1069821</link>
      <description>&lt;P&gt;can you make sure what other side is configured and match both side values.&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2020 11:20:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ask-about-associaton-lifetime/m-p/4078875#M1069821</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2020-05-04T11:20:32Z</dc:date>
    </item>
    <item>
      <title>Re: Ask about Associaton Lifetime</title>
      <link>https://community.cisco.com/t5/network-security/ask-about-associaton-lifetime/m-p/4078884#M1069822</link>
      <description>&lt;P&gt;Hi Sheraz,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will check it later in AWS, what happen if the value is different? i need information why is traffic state down periodcly 1 hour like i set on association lifetime&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your help&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2020 11:40:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ask-about-associaton-lifetime/m-p/4078884#M1069822</guid>
      <dc:creator>danielbusisa1410</dc:creator>
      <dc:date>2020-05-04T11:40:12Z</dc:date>
    </item>
    <item>
      <title>Re: Ask about Associaton Lifetime</title>
      <link>https://community.cisco.com/t5/network-security/ask-about-associaton-lifetime/m-p/4079124#M1069839</link>
      <description>&lt;P&gt;Hi Sheraz,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I got problem like in this pic, the traffic state is periodicly (1hour) change to 0,5. is this happen due to the association lifetime 3600 seconds? or it's normal when ipsec generated new key&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your kindly help&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture AWS.PNG" style="width: 961px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/73650i9859C1DA0B9CB8A0/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture AWS.PNG" alt="Capture AWS.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2020 17:03:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ask-about-associaton-lifetime/m-p/4079124#M1069839</guid>
      <dc:creator>danielbusisa1410</dc:creator>
      <dc:date>2020-05-04T17:03:15Z</dc:date>
    </item>
    <item>
      <title>Re: Ask about Associaton Lifetime</title>
      <link>https://community.cisco.com/t5/network-security/ask-about-associaton-lifetime/m-p/4079245#M1069847</link>
      <description>&lt;P&gt;do you see the tunnel going down too? when the key exchange happens the tunnel does not go down. could you share you config file. this behavior is not normal. you using ASA or its router? since when this happening?&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2020 20:40:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ask-about-associaton-lifetime/m-p/4079245#M1069847</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2020-05-04T20:40:25Z</dc:date>
    </item>
    <item>
      <title>Re: Ask about Associaton Lifetime</title>
      <link>https://community.cisco.com/t5/network-security/ask-about-associaton-lifetime/m-p/4079400#M1069849</link>
      <description>&lt;P&gt;Hi Sheraz,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your response,&lt;/P&gt;&lt;P&gt;What kind config do you want? or you just write the command what do you want here?&lt;/P&gt;&lt;P&gt;this just happen we still investigate and what happen when i set a lifetime association longer ? is there any problem on security if i changed longer?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2020 01:05:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ask-about-associaton-lifetime/m-p/4079400#M1069849</guid>
      <dc:creator>danielbusisa1410</dc:creator>
      <dc:date>2020-05-05T01:05:01Z</dc:date>
    </item>
    <item>
      <title>Re: Ask about Associaton Lifetime</title>
      <link>https://community.cisco.com/t5/network-security/ask-about-associaton-lifetime/m-p/4079955#M1069878</link>
      <description>&lt;P&gt;this just happen we still investigate and what happen when i set a lifetime association longer ? is there any problem on security if i changed longer?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you are security company or your company deal with a highly sensitive information between two remote side than its a good practice to rekey the lifetime association in short period of time. but if its not a very sensitive data than you can leave it as default. its all depend on your company security policies.&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2020 18:17:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ask-about-associaton-lifetime/m-p/4079955#M1069878</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2020-05-05T18:17:32Z</dc:date>
    </item>
  </channel>
</rss>

