<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IPSec peering Phase I Parameter in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ipsec-peering-phase-i-parameter/m-p/2467561#M270094</link>
    <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am having one S2S Tunnel where in Phase I below parameter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SA Lifetime:8 Hrs&lt;/P&gt;&lt;P&gt;Treaffic Volume:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 45M&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;Can I change this parameter in our end to below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SA Lifetime:24 Hrs&lt;/P&gt;&lt;P&gt;Volume: Not consider&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Query: Whether this Parameter is Remote side peering dependent&amp;nbsp; / I can chage the same in my Side only&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What exactly It will cause/ it it help us to keep the tunnel up for 24hrs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Br/Subhojit&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 03:41:57 GMT</pubDate>
    <dc:creator>subhojithalder198</dc:creator>
    <dc:date>2019-03-12T03:41:57Z</dc:date>
    <item>
      <title>IPSec peering Phase I Parameter</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-peering-phase-i-parameter/m-p/2467561#M270094</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am having one S2S Tunnel where in Phase I below parameter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SA Lifetime:8 Hrs&lt;/P&gt;&lt;P&gt;Treaffic Volume:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 45M&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;Can I change this parameter in our end to below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SA Lifetime:24 Hrs&lt;/P&gt;&lt;P&gt;Volume: Not consider&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Query: Whether this Parameter is Remote side peering dependent&amp;nbsp; / I can chage the same in my Side only&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What exactly It will cause/ it it help us to keep the tunnel up for 24hrs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Br/Subhojit&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:41:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-peering-phase-i-parameter/m-p/2467561#M270094</guid>
      <dc:creator>subhojithalder198</dc:creator>
      <dc:date>2019-03-12T03:41:57Z</dc:date>
    </item>
    <item>
      <title>IPSec peering Phase I Parameter</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-peering-phase-i-parameter/m-p/2467562#M270099</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems to me that you are talking about the Phase 2 parameters configured in the Crypto Map&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Generally I would say that its best to configure these as matching values per connection if needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To my understanding the Cisco documentation says that the VPN devices negotiate and choose the smallest values when comparing between the 2 devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That would seem to suggest that even if you changed your values the negotiation would go through but the remote ends values might be negotiated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I would suggest either changing these values with the remote end of the VPN or changing the parameters for this connection alone on your side and checking what values are negotiated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can for example get good information on an ASA with the command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show vpn-sessiondb detail l2l&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can further narrow it down with by using this command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show vpn-sessiondb detail l2l filter ipaddress &lt;VPN peer="" ip="" address=""&gt;&lt;/VPN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Though it seems that the second command even though supported doesnt seem to work on some softwares. Don't know why.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are couple of links related to configuring the Phase 2 SA lifetimes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configuration Guide:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa91/configuration/vpn/vpn_ike.html#wp1042781"&gt;http://www.cisco.com/en/US/docs/security/asa/asa91/configuration/vpn/vpn_ike.html#wp1042781&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Command Reference:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/command-reference/c8.html#wp2478892"&gt;http://www.cisco.com/en/US/docs/security/asa/command-reference/c8.html#wp2478892&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Feb 2014 13:38:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-peering-phase-i-parameter/m-p/2467562#M270099</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2014-02-07T13:38:59Z</dc:date>
    </item>
    <item>
      <title>IPSec peering Phase I Parameter</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-peering-phase-i-parameter/m-p/2467563#M270101</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree with Jouni that the configuration should be the same at both ends of the tunnel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But for the sake of argument, the SA lifetime parameter is not significant in the building of the VPN tunnel so these values can be different at both ends and the tunnel will still come up.&amp;nbsp; The lifetime value indicates when the device will send a re-key message to the peer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-- &lt;BR /&gt;Please remember to rate and select a correct answer&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Feb 2014 13:55:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-peering-phase-i-parameter/m-p/2467563#M270101</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-02-07T13:55:27Z</dc:date>
    </item>
    <item>
      <title>IPSec peering Phase I Parameter</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-peering-phase-i-parameter/m-p/2467564#M270103</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pls find the curretn capture&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;2 IKE Peer: &amp;lt;&lt;IP address=""&gt;&amp;gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Type : L2L Role : initiator &lt;/P&gt;&lt;P&gt;Rekey : no State : MM_ACTIVE &lt;/P&gt;&lt;P&gt;Encrypt : 3des Hash : MD5 &lt;/P&gt;&lt;P&gt;Auth : preshared Lifetime: &lt;STRONG&gt;28800&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Lifetime Remaining: &lt;STRONG&gt;5984&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Pls confirm , whether after 5984Sec my vpn tunnel will be down / IPsec tunnel will be down &amp;amp; up&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;In case Yes, what will be the erro-code in that case&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Br/Subhojit&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/IP&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Feb 2014 14:04:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-peering-phase-i-parameter/m-p/2467564#M270103</guid>
      <dc:creator>subhojithalder198</dc:creator>
      <dc:date>2014-02-07T14:04:48Z</dc:date>
    </item>
    <item>
      <title>IPSec peering Phase I Parameter</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-peering-phase-i-parameter/m-p/2467565#M270105</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The re-key will not cause any downtime.&amp;nbsp; You will, however, experience downtime if you change the lifetime since the ASA will need to rebuild the tunnel using the new parameters.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-- &lt;BR /&gt;Please remember to rate and select a correct answer&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Feb 2014 14:07:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-peering-phase-i-parameter/m-p/2467565#M270105</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-02-07T14:07:39Z</dc:date>
    </item>
  </channel>
</rss>

