09-20-2023 11:44 AM
If I change the DH group in an ISAKMP policy, will the tunnel automatically start using that group after a period, or do I have to bounce the tunnel interface? I know that bouncing the interface works to get it to switch over immediately. But it would be preferable for it to start using the new group automatically without bouncing the interface.
Solved! Go to Solution.
09-20-2023 02:00 PM
The good news is that policies for the ipsec tunnel are negotiated for a period of time, and when that time is about to expire there is a new negotiation, which would use the new policy. So if you are not a hurry to get the new policy being used then do not bounce and just wait.
09-20-2023 02:00 PM
The good news is that policies for the ipsec tunnel are negotiated for a period of time, and when that time is about to expire there is a new negotiation, which would use the new policy. So if you are not a hurry to get the new policy being used then do not bounce and just wait.
09-20-2023 02:12 PM
I am glad that my explanation was helpful. Thank you for marking this question as solved. This will help other participants in the community to identify discussions which have helpful information. This community is an excellent place to ask questions and to learn about networking. I hope to see you continue to be active in the community.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: