06-06-2018 07:30 PM - edited 03-12-2019 05:21 AM
Dear Members,
Please help me out one of behavior I am facing in my customer network.
We are running IKEv2 on one pf the gre tunnel and that tunnel keep reset after every 24 Hours . On rest of tunnel we are running IKEv1 but those tunnel don't get reset.
Can someone enlighten me why I am facing such a behavior
Security association lifetime value are default.
06-07-2018 02:38 AM
06-07-2018 04:14 AM
Thanks for response.
Please find your answers below:
Spoke site is CISCO881-SEC-K9
Hub is CISCO2921
DPD is configured.
crypto ikev2 dpd 40 5 on-demand
In general Tunnel up time never goes beyond 24 Hours. Once tunnel uptime reach 24 hours it uptime timers once again start.
06-07-2018 04:35 AM
06-07-2018 05:14 AM
I am running sh crypto session details to see the output and yes I am referring to Ikev2 timers.
My concern is that why for ikev1 tunnels uptime is more than 24 hours, even though we have manually configured set security-association lifetime for 8 Hours and for ikev2 it is not more than 24 Hours.
Just want to know logic.
As tunnel up time is less than 24 Hours I am not able to handover the router to other team.
06-07-2018 05:29 AM
06-07-2018 05:48 AM
Even I think so but not able to figure out why for Ikev1 tunnel uptime is more than 24 Hours?
just want to know one thing if suppose no traffic goes via Ikev2 tunnel for last 24 Hours then ikev2 tunnel uptime timer will reset?
06-07-2018 06:16 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide