cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
608
Views
15
Helpful
2
Replies

Ipsec L2L VPN Idle timeout

Pawan Raut
Level 4
Level 4

What is the risk associated with increasing the idle timeout value for IPsec site to site VPN or disabling the idle timeout for IPsec site to site VPN.

2 Replies 2

@Pawan Raut you'd probably want to ensure the same value is configured on both ends to ensure there is no mismatched timers. Alternatively use a VTI, the tunnel will always be up.

Even so idle timeout is increase, still there is isakmp time which make borh peer re establish tunnel after defualt 24 hr.

Idle timeout use with dpd where the dpd have two criteria  to work

1-idle timeout is end

2- the rourer need to send traffic  to other peer.

When idle is high then dpd not work probably.