cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
342
Views
0
Helpful
3
Replies

New IPSec SAs what are decision criterios

andre.frost
Level 1
Level 1

Hi

when IPSec SAs lifetimes over new SAs are etablished but only if traffice is happens, what are the thresholds or how is decided if new SAs are established and how to change this,

does anybody knows a dokument, I had one on CCO but I cannot find it again

3 Replies 3

mmellet
Level 3
Level 3

Use ‘set security-association lifetime {seconds | kilobytes}’ to change the defaults.

I know that, but the question is another.

When this lifetime expires, under which circumstances is a new sa creates or not ?

It’s probably defined in an RFC somewhere. I couldn’t find it at a glance. You might check with your Cisco rep.