- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-20-2023 11:44 AM
If I change the DH group in an ISAKMP policy, will the tunnel automatically start using that group after a period, or do I have to bounce the tunnel interface? I know that bouncing the interface works to get it to switch over immediately. But it would be preferable for it to start using the new group automatically without bouncing the interface.
Solved! Go to Solution.
- Labels:
-
Other Routing
-
Routing Protocols
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-20-2023 02:00 PM
The good news is that policies for the ipsec tunnel are negotiated for a period of time, and when that time is about to expire there is a new negotiation, which would use the new policy. So if you are not a hurry to get the new policy being used then do not bounce and just wait.
Rick
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-20-2023 02:00 PM
The good news is that policies for the ipsec tunnel are negotiated for a period of time, and when that time is about to expire there is a new negotiation, which would use the new policy. So if you are not a hurry to get the new policy being used then do not bounce and just wait.
Rick
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-20-2023 02:12 PM
I am glad that my explanation was helpful. Thank you for marking this question as solved. This will help other participants in the community to identify discussions which have helpful information. This community is an excellent place to ask questions and to learn about networking. I hope to see you continue to be active in the community.
Rick
