cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1678
Views
0
Helpful
8
Replies

VPN Lifetimes and the effects

Marco Serato
Level 1
Level 1

Hello

The following question is just for understanding.

Does a VPN tunnel collapse or abort briefly when the IKE Liftetime has expired?

With IPSEC SA, the lifetimes are required for rekeying- Is that correct?

Thanks Martin

 

2 Accepted Solutions

Accepted Solutions

Does a VPN tunnel collapse or abort briefly when the IKE Liftetime has expired? no because both side choose one lifetime. 

With IPSEC SA, the lifetimes are required for rekeying- Is that correct? Yes when IPSec SA lifetime is end the both peer start exchange phase2 rekey for new key.

View solution in original post

@Marco Serato no the VPN tunnel does not collapse when the IKE SA lifetime expires. Dataplane traffic over the VPN uses the IPSec SA not the IKE SA.

 

View solution in original post

8 Replies 8

Does a VPN tunnel collapse or abort briefly when the IKE Liftetime has expired? no because both side choose one lifetime. 

With IPSEC SA, the lifetimes are required for rekeying- Is that correct? Yes when IPSec SA lifetime is end the both peer start exchange phase2 rekey for new key.

After the IKE Lifetime has expired, is there only one rekeying or is there more to it?

Depending if you config per-host 

Then for each host in acl subnet there rekey

If not then only one rekey.

Is the rekeying not based on the Diffie Hellman algo?

@Marco Serato no the VPN tunnel does not collapse when the IKE SA lifetime expires. Dataplane traffic over the VPN uses the IPSec SA not the IKE SA.

 

Marco Serato
Level 1
Level 1

Many thanks for the answers.

In IKEv2 the IKE lifetime must be the same, but the SA lifetime can be different. Am I correct?

@Marco Serato no, with IKEV2 the configured lifetimes do not need to be identical. If the two peers have different lifetime policies, the end with the shorter lifetime will end up always being the one to request the rekeying.

https://networkengineering.stackexchange.com/questions/6622/getting-cisco-isakmp-and-ipsec-sa-lifetime-confused

I think you confuse about the two lifetime in IPsec, check link above for more info