05-21-2014 11:55 PM
why VPNs' phase1 keylife must be greater than the phase 2 keylife and what will happen if phase2 keylife is greater than the phase1 keylife?
Solved! Go to Solution.
09-09-2014 04:17 PM
Ccryshna1,
As your Phase 1 (IKE) SA is used to secure a channel for control plane traffic, it must be established in order to establish or re-establish your Phase 2 SA. Therefore, if your Phase 1 lifetime is shorter than your Phase 2 lifetime, you must establish a new Phase 1 SA every time Phase 2 rekeys. If you are using Main Mode and Quick Mode, this is an extra six packet exchange which must occur at each Phase 2 rekey.
HTH,
Frank
09-09-2014 04:17 PM
Ccryshna1,
As your Phase 1 (IKE) SA is used to secure a channel for control plane traffic, it must be established in order to establish or re-establish your Phase 2 SA. Therefore, if your Phase 1 lifetime is shorter than your Phase 2 lifetime, you must establish a new Phase 1 SA every time Phase 2 rekeys. If you are using Main Mode and Quick Mode, this is an extra six packet exchange which must occur at each Phase 2 rekey.
HTH,
Frank
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide