cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
668
Views
0
Helpful
1
Replies

TCP conn after Phase 2 lifetime

jshailes1
Level 1
Level 1

I was wondering what happens when a tcp conn is active and the phase 2 lifetime is reached? Would the tunnel be re-established and the tcp connection live on or would a fin or rst be generated by the firewall or would something else happen?

1 Reply 1

Parminder Sian
Level 1
Level 1

Hi James,

Answer:

The TCP connection will live and wont go down.

Reason:

When phase 2 life time is about to expire, few seconds before that a new SPI is generated with all counters set to zero, so when the original phase 2 lifetime expires, second SPI takes over. This keep the TCP connection active.

Parminder Sian