<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ike phase 1 lifetime, asa with netscreen in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ike-phase-1-lifetime-asa-with-netscreen/m-p/1244445#M834851</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i've never seen that before, especially if the lifetime is the same on both sides.&lt;/P&gt;&lt;P&gt;what is the output of "show isa sa detail" on the cisco equipment, and the equivalent output on the other hardware?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 10 Jun 2009 14:53:46 GMT</pubDate>
    <dc:creator>srue</dc:creator>
    <dc:date>2009-06-10T14:53:46Z</dc:date>
    <item>
      <title>ike phase 1 lifetime, asa with netscreen</title>
      <link>https://community.cisco.com/t5/network-security/ike-phase-1-lifetime-asa-with-netscreen/m-p/1244444#M834850</link>
      <description>&lt;P&gt;Hi  all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ipsec, L2L, in configuration I set 8h, on both side&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   IKE Peer: x.y.z.w&lt;/P&gt;&lt;P&gt;    Type    : L2L             Role    : initiator&lt;/P&gt;&lt;P&gt;    Rekey   : no              State   : MM_ACTIVE&lt;/P&gt;&lt;P&gt;    Encrypt : 3des            Hash    : SHA&lt;/P&gt;&lt;P&gt;    Auth    : preshared       Lifetime: 28800&lt;/P&gt;&lt;P&gt;    Lifetime Remaining: 24897&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but in logs, keys are changing in every 6 hours:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jun  6 11:17:46 masterasa Jun 06 2009 11:17:46: %ASA-4-713903: Group = x.y.z.w, IP = x.y.z.w Freeing previously allocated memory for authorization-dn-attributes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jun  6 17:17:46 masterasa Jun 06 2009 17:17:46: %ASA-4-713903: Group = x.y.z.w, IP = x.y.z.w, Freeing previously allocated memory for authorization-dn-attributes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jun  6 23:17:46 masterasa Jun 06 2009 23:17:46: %ASA-4-713903: Group = x.y.z.w, IP = x.y.z.w , Freeing previously allocated memory for authorization-dn-attributes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jun  7 05:17:47 masterasa Jun 07 2009 05:17:47: %ASA-4-713903: Group = x.y.z.w, IP = x.y.z.w, Freeing previously allocated memory for authorization-dn-attributes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Someone knows what's reason of that ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:41:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ike-phase-1-lifetime-asa-with-netscreen/m-p/1244444#M834850</guid>
      <dc:creator>pawel1942</dc:creator>
      <dc:date>2019-03-11T15:41:46Z</dc:date>
    </item>
    <item>
      <title>Re: ike phase 1 lifetime, asa with netscreen</title>
      <link>https://community.cisco.com/t5/network-security/ike-phase-1-lifetime-asa-with-netscreen/m-p/1244445#M834851</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i've never seen that before, especially if the lifetime is the same on both sides.&lt;/P&gt;&lt;P&gt;what is the output of "show isa sa detail" on the cisco equipment, and the equivalent output on the other hardware?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Jun 2009 14:53:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ike-phase-1-lifetime-asa-with-netscreen/m-p/1244445#M834851</guid>
      <dc:creator>srue</dc:creator>
      <dc:date>2009-06-10T14:53:46Z</dc:date>
    </item>
    <item>
      <title>Re: ike phase 1 lifetime, asa with netscreen</title>
      <link>https://community.cisco.com/t5/network-security/ike-phase-1-lifetime-asa-with-netscreen/m-p/1244446#M834852</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it's my sh crypto isakmp sa detail&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IKE Peer: x.y.z.w&lt;/P&gt;&lt;P&gt;Type    : L2L&lt;/P&gt;&lt;P&gt;Role    : initiator&lt;/P&gt;&lt;P&gt;Rekey   : no&lt;/P&gt;&lt;P&gt;State   : MM_ACTIVE&lt;/P&gt;&lt;P&gt;Encrypt : 3des&lt;/P&gt;&lt;P&gt;Hash    : SHA&lt;/P&gt;&lt;P&gt;Auth    : preshared       Lifetime: 28800&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;    Lifetime Remaining: 12134&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;my conf:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto isakmp policy 10&lt;/P&gt;&lt;P&gt; authentication pre-share&lt;/P&gt;&lt;P&gt; encryption 3des&lt;/P&gt;&lt;P&gt; hash sha&lt;/P&gt;&lt;P&gt; group 2&lt;/P&gt;&lt;P&gt; lifetime 28800&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the netscreen side is  exactly the same&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i don't have any idea what's the reason of this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;greetings&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Jun 2009 13:01:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ike-phase-1-lifetime-asa-with-netscreen/m-p/1244446#M834852</guid>
      <dc:creator>pawel1942</dc:creator>
      <dc:date>2009-06-12T13:01:39Z</dc:date>
    </item>
  </channel>
</rss>

