cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3859
Views
0
Helpful
1
Replies

VPNs Phase 1 Keylife vs Phase 2 keylife

Ccryshna1
Level 1
Level 1

why VPNs' phase1 keylife must be greater than the phase 2 keylife and what will happen if phase2 keylife is greater than the phase1 keylife?

 

1 Accepted Solution

Accepted Solutions

Frank DeNofa
Cisco Employee
Cisco Employee

Ccryshna1,

 

As your Phase 1 (IKE) SA is used to secure a channel for control plane traffic, it must be established in order to establish or re-establish your Phase 2 SA. Therefore, if your Phase 1 lifetime is shorter than your Phase 2 lifetime, you must establish a new Phase 1 SA every time Phase 2 rekeys. If you are using Main Mode and Quick Mode, this is an extra six packet exchange which must occur at each Phase 2 rekey.

 

HTH,

Frank

View solution in original post

1 Reply 1

Frank DeNofa
Cisco Employee
Cisco Employee

Ccryshna1,

 

As your Phase 1 (IKE) SA is used to secure a channel for control plane traffic, it must be established in order to establish or re-establish your Phase 2 SA. Therefore, if your Phase 1 lifetime is shorter than your Phase 2 lifetime, you must establish a new Phase 1 SA every time Phase 2 rekeys. If you are using Main Mode and Quick Mode, this is an extra six packet exchange which must occur at each Phase 2 rekey.

 

HTH,

Frank