Is it ok to set ipsec phase 1 lifetime 24 hours when the peer set it to 86400 secs?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Is it ok to set ipsec phase 1 lifetime 24 hours when the peer set it to 86400 secs?

L2 Linker

Hello

I made ipsec tunnel between paloalto and fortigate.

 

I keep have issue about rekeying, so I try to set different lifetime phase 1 and 2.

phase 1 : 28800 -> 86400

phase 2 : 28800 -> 28800

 

In paloalto I can't set 86400 sec, so I plan to set it 24 hours.

 

Is it okay to set it that way? Because fortigate will set the value to 86400 sec.

2 REPLIES 2

L7 Applicator

The lifetime values really should be the same.  You should ask the other side if they are able to set something that is available on the PAN.

 

Tunnels do sometimes work with different lifetimes set.  But the operations can be inconsistent and have problems like suddently stop passing traffic when one side or the other lifetime expires.

 

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center

Thanks for your answer,

 

Because the values are same duration, so I guess it's fine but I'm not sure..

In some blog or article on internet, they set the values to hour-second.

 

Hope it'll work well

  • 6776 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!