<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Site to site VPN issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-issue/m-p/28368#M20735</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Folks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an issue with some site-to-site configurations that is bugging the cr*p out of me, and I thought I'd post it here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I run some site-to-site VPN's (Palo Alto to Cisco 887 routers) which come up fine, but which seem to defy *all* configuration with respect to IpSec SA lifetime.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as I can tell, I've configured a 12 hour (43200 second) lifetime, yet when the IPSec is negotiated, I get this in the logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IPSec key installed. Installed SA: www.xxx.yyy.zzz[500]-aaa.bbb.ccc.ddd[500] SPI:0x8AA8C96C/0x49847307 lifetime 3600 Sec lifesize 4608000 KB.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note the "3600 Sec" lifetime - which is only 1 hour.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, this is not a real big deal - apart from adding extra lines into my logs, it's not a real hassle - but it's just peeving me off that I can't solve it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there anywhere else I should look for lifetime settings besides the "IPSec Crypto" setting int he network configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 22 Jan 2013 00:24:15 GMT</pubDate>
    <dc:creator>darren_g</dc:creator>
    <dc:date>2013-01-22T00:24:15Z</dc:date>
    <item>
      <title>Site to site VPN issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-issue/m-p/28368#M20735</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Folks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an issue with some site-to-site configurations that is bugging the cr*p out of me, and I thought I'd post it here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I run some site-to-site VPN's (Palo Alto to Cisco 887 routers) which come up fine, but which seem to defy *all* configuration with respect to IpSec SA lifetime.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as I can tell, I've configured a 12 hour (43200 second) lifetime, yet when the IPSec is negotiated, I get this in the logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IPSec key installed. Installed SA: www.xxx.yyy.zzz[500]-aaa.bbb.ccc.ddd[500] SPI:0x8AA8C96C/0x49847307 lifetime 3600 Sec lifesize 4608000 KB.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note the "3600 Sec" lifetime - which is only 1 hour.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, this is not a real big deal - apart from adding extra lines into my logs, it's not a real hassle - but it's just peeving me off that I can't solve it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there anywhere else I should look for lifetime settings besides the "IPSec Crypto" setting int he network configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jan 2013 00:24:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-issue/m-p/28368#M20735</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2013-01-22T00:24:15Z</dc:date>
    </item>
    <item>
      <title>Re: Site to site VPN issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-issue/m-p/28369#M20736</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Never mind, found the issue - had to tweak the Cisco end a bit to get it to accept the additional time frame parameters.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All good now. No more excessive log entries!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jan 2013 01:01:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-issue/m-p/28369#M20736</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2013-01-22T01:01:49Z</dc:date>
    </item>
  </channel>
</rss>

