cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
573
Views
0
Helpful
1
Replies

can I change IKE,Transform set... without affecting IPSEC tunnels?

zhichao
Level 1
Level 1

Hi

In the production network, can I change the IPSEC parameters, e.g. SA life time, Pre-shared key, etc...? Will these affect the tunnels?

1 Accepted Solution

Accepted Solutions

gfullage
Cisco Employee
Cisco Employee

You can change them, they won't be used until the tunnel is rebuilt (every 1 hour by default for Phase 2 SA's, and every 24 hours for Phase 1). Make sure you change them on both sides of the tunnel though so they match up.

View solution in original post

1 Reply 1

gfullage
Cisco Employee
Cisco Employee

You can change them, they won't be used until the tunnel is rebuilt (every 1 hour by default for Phase 2 SA's, and every 24 hours for Phase 1). Make sure you change them on both sides of the tunnel though so they match up.