01-28-2022 02:16 AM - edited 01-28-2022 02:20 AM
Hello all,
I am creating a script to simulate the traffic in my isakmp. For this, I am looking for the lifetime of the isakmp tunnel so that I can align myself correctly with it to keep it active and avoid it deactivating after a while.
Where can I find its lifetime? I tried the command ''show crypto isakmp policy'' but I don't know if this is the right place.
Thanks in advance for your answer
Mickaël.
Solved! Go to Solution.
01-28-2022 02:49 AM
"show crypto isakmp policy" is the right place to see your configured lifetime. But it is negotiated with the peer so it could be lower. With "show crypto isakmp sa detail" you can see the remaining lifetime and in the debug you see what got negotiated.
With IKEv2 it's getting a little more complex as both peers can have individual lifetimes.
If you want to keep the tunnel up, just trigger your traffic frequently.
01-28-2022 02:49 AM
"show crypto isakmp policy" is the right place to see your configured lifetime. But it is negotiated with the peer so it could be lower. With "show crypto isakmp sa detail" you can see the remaining lifetime and in the debug you see what got negotiated.
With IKEv2 it's getting a little more complex as both peers can have individual lifetimes.
If you want to keep the tunnel up, just trigger your traffic frequently.
01-28-2022 05:01 AM
Hello,
I appreciate you answering me,
Okay, I see.
Thank you for your reply.
01-28-2022 02:02 PM
Just to add on this what Karsten said. if you running isakmp version 1 in this case lower lifetime vaule will have a priority between two peers. let say site A router isakmp lifetime set as 8600 and site B router isakmp lifetime is 2200. in this case the lower value have priority and SiteA router will adjust itself to SiteB. either if Site A is the vpn-tunnel initatior or responder.
if running the isakmp version 2 in that case lifetime does not matter.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide