• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 421
  • Last Modified:

VPN Configuration

I have to put a VPN from an ASA5505 to a Cisco VPN concentrator - no problem - however

In the documentation from the owners of the Concentrator they have asked that I set

IPSEC SA Lifetime
  460800 Kilobytes
  28800 Seconds

At the moment my VPN has the default policy of

 lifetime 86400

I can change that easy enough but I cant see how to set a data limit in kilobytes?
0
Pete Long
Asked:
Pete Long
  • 3
1 Solution
 
lrmooreCommented:
If you're using the ASDM GUI:
Configuration | VPN | IPSEC | IPSec Rules
Select the tunnel policy | Edit
 Tunnel Policy (Crypto Map) - Advanced tab
   Security Association Lifetime settings
   Time:    [  8 ] : [ 0 ] :  [ 0 ] hrs min sec  <== default
   Traffic Volume: 4608000  <== default

Default 8 hours = 28800 Seconds
Required Kilobytes is the default
Default settings don't necessarily show up in the configs.

Your IKE lifetime is not the same as the SA lifetime. The IKE lifetime default is 86400.
If the l2l tunnel is working, don't mess with the settings.
0
 
Pete LongConsultantAuthor Commented:
Cheers Les - Will be testing it in the morning :)
0
 
Pete LongConsultantAuthor Commented:
Came up no problem cheers - now I need to change it > next Question..
http://www.experts-exchange.com/?qid=22491286
0
 
Pete LongConsultantAuthor Commented:
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

  • 3
Tackle projects and never again get stuck behind a technical roadblock.
Join Now