04-12-2017 01:57 AM
If i set lifetime for phase 1 ISAKMP equal 3600 seconds, has it sense to set PFS and lifetime for phase 2 IPSec equal 3600 seconds? I understand it's sufficently to set only PFS and lifetime of phase 2, because anyhow after 3600 sec. PFS enforces new phase 1 tunnel and new key materials.
Could you refer to this? Thanks for help in advance!
04-13-2017 01:31 AM
I do not see any great reason to keep both same for phase -1 and phase -2 . Best practice phase-1 should always be greater than phase-2.
Ajay
04-13-2017 02:01 AM
Ok, what in case when phase1 is greater than phase2? Is it lifetime of phase1 has any meaning? Because when lifetime of phase2 expires then new phase1 is enforced.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide