we are moving a lot of ipsec vpn tunnels to an ASA in the coming weeks, most of them have the default ipsec SA lifetime of 28,800, but there are a few that have different values. Do I need to manually set those that differ in their respective crypto map, or will the default suffice and the ASA will negotiate any differences with the other end?