<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSec lifetime configuration - FDM in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ipsec-lifetime-configuration-fdm/m-p/3949234#M935865</link>
    <description>&lt;P&gt;Hello Marvin,&lt;/P&gt;&lt;P&gt;Thank you for the reply. Is there any way to configure this?&amp;nbsp;And what is the default value used by FirePower for lifetime in Phase 2?&lt;/P&gt;&lt;P&gt;Btw, I'm really surprised with this information. IPsec lifetime is one of the basic configuration parameters for IKE protocol.&lt;/P&gt;</description>
    <pubDate>Mon, 28 Oct 2019 14:45:03 GMT</pubDate>
    <dc:creator>ivan.kusturic</dc:creator>
    <dc:date>2019-10-28T14:45:03Z</dc:date>
    <item>
      <title>IPSec lifetime configuration - FDM</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-lifetime-configuration-fdm/m-p/3949209#M935863</link>
      <description>&lt;P&gt;Hello everybody,&lt;/P&gt;&lt;P&gt;I'm trying to find out where to specify IKE Phase 2 Lifetime duration (IPSec lifetime)? Under objects, you can only define lifetime for IKE Policies - Phase 1.&lt;/P&gt;&lt;P&gt;Software version is 6.3 and configuration is being done via FDM. Appliance is FirePower 2110.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:38:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-lifetime-configuration-fdm/m-p/3949209#M935863</guid>
      <dc:creator>ivan.kusturic</dc:creator>
      <dc:date>2020-02-21T17:38:16Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec lifetime configuration - FDM</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-lifetime-configuration-fdm/m-p/3949218#M935864</link>
      <description>&lt;P&gt;Unfortunately the necessary command is not supported in FDM - even when using Flexconfig.&lt;/P&gt;
&lt;P&gt;Reference:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvo91921/?rfs=iqvred" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvo91921/?rfs=iqvred&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;The BugID says it affects through 6.4.&amp;nbsp; I just verified that even my 6.5 FTD device (managed by FDM) continues to blacklist the command.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2019 14:24:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-lifetime-configuration-fdm/m-p/3949218#M935864</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-10-28T14:24:57Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec lifetime configuration - FDM</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-lifetime-configuration-fdm/m-p/3949234#M935865</link>
      <description>&lt;P&gt;Hello Marvin,&lt;/P&gt;&lt;P&gt;Thank you for the reply. Is there any way to configure this?&amp;nbsp;And what is the default value used by FirePower for lifetime in Phase 2?&lt;/P&gt;&lt;P&gt;Btw, I'm really surprised with this information. IPsec lifetime is one of the basic configuration parameters for IKE protocol.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2019 14:45:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-lifetime-configuration-fdm/m-p/3949234#M935865</guid>
      <dc:creator>ivan.kusturic</dc:creator>
      <dc:date>2019-10-28T14:45:03Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec lifetime configuration - FDM</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-lifetime-configuration-fdm/m-p/3949244#M935868</link>
      <description>&lt;P&gt;It can be configured if you switch to FMC management. However you cannot configure it via FXOS or Lina CLI.&lt;/P&gt;
&lt;P&gt;You're right it's a pretty basic setting. I keep pushing Cisco on achieving feature parity for basic things like this between ASA and FTD - no matter what management platform is used.&lt;/P&gt;
&lt;P&gt;No excuse, but by way of explanation I'm told it's an architectural issue since FMD (and CDO) only support settings for which there is an API while FMC interacts with the Lina and clish running-configs directly. Cisco continues to enhance the API with every new release but it's still not where it needs to be.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2019 14:48:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-lifetime-configuration-fdm/m-p/3949244#M935868</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-10-28T14:48:59Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec lifetime configuration - FDM</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-lifetime-configuration-fdm/m-p/3949254#M935869</link>
      <description>&lt;P&gt;Marvin, thank you very much for the answer and explanation.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Ivan&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2019 19:23:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-lifetime-configuration-fdm/m-p/3949254#M935869</guid>
      <dc:creator>ivan.kusturic</dc:creator>
      <dc:date>2019-10-28T19:23:13Z</dc:date>
    </item>
  </channel>
</rss>

