06-25-2024 01:21 PM - edited 06-25-2024 01:23 PM
Hi all,
hope you can help me.
I'm having my mind melted with the Keychain Accept and Lifetimes, basically I'm getting confused from all the info I see.
Please would it be possible to confirm if the below is correct?
key chain TEST
key 6
accept-lifetime local 10:00:00 Jun 12 2024 14:00:00 Dec 12 2024
send-lifetime local 11:00:00 Jun 12 2024 13:00:00 Dec 12 2024
key 7
accept-lifetime local 10:00:00 Dec 11 2024 14:00:00 Jun 13 2025
send-lifetime local 11:00:00 Dec 11 2024 13:00:00 Jun 13 2025
key 8
accept-lifetime local 10:00:00 Jun 12 2025 14:00:00 Dec 12 2025
send-lifetime local 11:00:00 Jun 12 2025 13:00:00 Dec 12 2025
key 9
accept-lifetime local 10:00:00 Dec 11 2025 14:00:00 Jun 13 2026
send-lifetime local 11:00:00 Dec 11 2025 13:00:00 Jun 13 2026
key 10
accept-lifetime local 10:00:00 Jun 12 2026 14:00:00 Dec 12 2026
send-lifetime local 11:00:00 Jun 12 2026 13:00:00 Dec 12 2026
key 11
accept-lifetime local 10:00:00 Dec 11 2026 14:00:00 Jun 13 2027
send-lifetime local 11:00:00 Dec 11 2026 13:00:00 Jun 13 2027
key 12
accept-lifetime local 10:00:00 Jun 12 2027 14:00:00 Dec 12 2027
send-lifetime local 11:00:00 Jun 12 2027 13:00:00 Dec 12 2027
key 13
accept-lifetime local 10:00:00 Dec 11 2027 14:00:00 Jun 13 2028
send-lifetime local 11:00:00 Dec 11 2027 13:00:00 Jun 13 2028
key 14
accept-lifetime local 10:00:00 Jun 12 2028 14:00:00 Dec 12 2028
send-lifetime local 11:00:00 Jun 12 2028 13:00:00 Dec 12 2028
key 15
accept-lifetime local 10:00:00 Dec 11 2028 14:00:00 Jun 13 2029
send-lifetime local 11:00:00 Dec 11 2028 13:00:00 Jun 13 2029
key 16
accept-lifetime local 10:00:00 Jun 12 2029 14:00:00 Dec 12 2029
send-lifetime local 11:00:00 Jun 12 2029 13:00:00 Dec 12 2029
key 17
accept-lifetime local 10:00:00 Dec 11 2029 14:00:00 Jun 13 2030
send-lifetime local 11:00:00 Dec 11 2029 13:00:00 Jun 13 2030
key 18
accept-lifetime local 10:00:00 Jun 12 2030 14:00:00 Dec 12 2030
send-lifetime local 11:00:00 Jun 12 2030 13:00:00 Dec 12 2030
key 19
accept-lifetime local 10:00:00 Dec 11 2030 14:00:00 Jun 13 2031
send-lifetime local 11:00:00 Dec 11 2030 13:00:00 Jun 13 2031
key 20
accept-lifetime local 10:00:00 Jun 12 2031 14:00:00 Dec 12 2031
send-lifetime local 11:00:00 Jun 12 2031 13:00:00 Dec 12 2031
key 21
accept-lifetime local 10:00:00 Dec 11 2031 14:00:00 Jun 13 2032
send-lifetime local 11:00:00 Dec 11 2031 13:00:00 Jun 13 2032
key 22
accept-lifetime local 10:00:00 Jun 12 2032 14:00:00 Dec 12 2032
send-lifetime local 11:00:00 Jun 12 2032 13:00:00 Dec 12 2032
key 23
accept-lifetime local 10:00:00 Dec 11 2032 14:00:00 Jun 13 2033
send-lifetime local 11:00:00 Dec 11 2032 13:00:00 Jun 13 2033
key 24
accept-lifetime local 10:00:00 Jun 12 2033 14:00:00 Dec 12 2033
send-lifetime local 11:00:00 Jun 12 2033 13:00:00 Dec 12 2033
key 25
accept-lifetime local 10:00:00 Dec 11 2033 14:00:00 Jun 13 2034
send-lifetime local 11:00:00 Dec 11 2033 13:00:00 Jun 13 2034
key 26
accept-lifetime local 10:00:00 Jun 12 2034 14:00:00 Dec 12 2034
send-lifetime local 11:00:00 Jun 12 2034 13:00:00 Dec 12 2034
key 27
accept-lifetime local 10:00:00 Dec 11 2034 14:00:00 Jun 13 2035
send-lifetime local 11:00:00 Dec 11 2034 13:00:00 Jun 13 2035
key 28
accept-lifetime local 10:00:00 Jun 12 2035 infinite
send-lifetime local 11:00:00 Jun 12 2035 infinite
For what I see and understand, there's always a key overlapping by one day, so the data should always be flowing uninterruptedly, but really wanted to be sure, since really don't want the network to drop. Hope you can advise.
Thank you
Solved! Go to Solution.
06-25-2024 10:51 PM
that should as expected- make sure peer also have same timings.
If one authenticated and another one non authentication, neighborship go down, cause network tier down.
06-26-2024 06:04 AM - edited 06-26-2024 06:04 AM
Hello
@Othacon wrote:
For what I see and understand, there's always a key overlapping by one day
Correct until it reaches key 28 and then its infinite and no key rolling will occur thereafter
06-25-2024 10:51 PM
that should as expected- make sure peer also have same timings.
If one authenticated and another one non authentication, neighborship go down, cause network tier down.
06-26-2024 06:04 AM - edited 06-26-2024 06:04 AM
Hello
@Othacon wrote:
For what I see and understand, there's always a key overlapping by one day
Correct until it reaches key 28 and then its infinite and no key rolling will occur thereafter
06-26-2024 06:07 AM
Would also suggest apply some higher security if applicable.
example:
key chain TEST
key x
cryptographic-algorithm hmac-sha-512
06-27-2024 02:41 AM
Thank you @paul driver and @balaji.bandi , was going "crazy" just updated the keys.
The last key was really because IOS wouldn't let me put more keys than the year 2035 so really had to go for infinite. Need to put a new IOS version and try, maybe now has more than the year 2035 has a limit.
06-27-2024 03:50 AM
Hello
Note: Once you get into key7 you can at anytime thereafter reuse/modify key6 etc.... as the keys are all based on your switches/rtrs system time.
06-27-2024 03:54 AM
I wait to answer you to see using last key with and without infinite keyword
as I know when router detect it use last key it change the duration to be infinite by default to prevent return to un-auth status
but I want to be sure before I answer you
please confirm if you want lab check this status or not
MHM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide