Solved

VPN Configuration

Posted on 2007-04-03
4
398 Views
Last Modified: 2008-01-09
I have to put a VPN from an ASA5505 to a Cisco VPN concentrator - no problem - however

In the documentation from the owners of the Concentrator they have asked that I set

IPSEC SA Lifetime
  460800 Kilobytes
  28800 Seconds

At the moment my VPN has the default policy of

 lifetime 86400

I can change that easy enough but I cant see how to set a data limit in kilobytes?
0
Comment
Question by:Pete Long
  • 3
4 Comments
 
LVL 79

Accepted Solution

by:
lrmoore earned 500 total points
ID: 18842711
If you're using the ASDM GUI:
Configuration | VPN | IPSEC | IPSec Rules
Select the tunnel policy | Edit
 Tunnel Policy (Crypto Map) - Advanced tab
   Security Association Lifetime settings
   Time:    [  8 ] : [ 0 ] :  [ 0 ] hrs min sec  <== default
   Traffic Volume: 4608000  <== default

Default 8 hours = 28800 Seconds
Required Kilobytes is the default
Default settings don't necessarily show up in the configs.

Your IKE lifetime is not the same as the SA lifetime. The IKE lifetime default is 86400.
If the l2l tunnel is working, don't mess with the settings.
0
 
LVL 57

Author Comment

by:Pete Long
ID: 18842781
Cheers Les - Will be testing it in the morning :)
0
 
LVL 57

Author Comment

by:Pete Long
ID: 18849368
Came up no problem cheers - now I need to change it > next Question..
http://www.experts-exchange.com/?qid=22491286
0
 
LVL 57

Author Comment

by:Pete Long
ID: 18849370
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Some of you may have heard that SonicWALL has finally released an app for iOS devices giving us long awaited connectivity for our iPhone's, iPod's, and iPad's. This guide is just a quick rundown on how to get up and running quickly using the app. …
For months I had no idea how to 'discover' the IP address of the other end of a link (without asking someone who knows), and it drove me batty. Think about it. You can't use Cisco Discovery Protocol (CDP) because it's not implemented on the ASAs.…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

821 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question