Avatar of timbrigham
timbrigham
Flag for United States of America asked on

Forefront VPN Phase 1 timer

My Forefront TMG server is producing some unusual behavior for it's phase 1 negotiation with it's counterpart (a Cisco VPN concentrator). I have the phase 1 value set to 86400 seconds in Forefront. The Cisco device sees it as negotiating to 7200 seconds.

Why is the value that I have entered not applied?
Microsoft Forefront ISA ServerCisco

Avatar of undefined
Last Comment
timbrigham

8/22/2022 - Mon
Keith Alabaster

Sorry Tim - we gave up our Cisco 3000 series devices quite some time ago so have no way to pursue this.
timbrigham

ASKER
Keith, I just checked out the IP Security Monitor MMC snapin on my Forefront box. The settings there display as 0KB / 7200 seconds. Aren't these settings supposed to reflect the settings entered into Forefront? I also checked out another VPN tunnel we have set up (another Cisco device, an older PIX). Same issue.
If it were negotiated value from my remote devices it should be being set to the 86400 .
Keith Alabaster

Looking
Experts Exchange is like having an extremely knowledgeable team sitting and waiting for your call. Couldn't do my job half as well as I do without it!
James Murphy
ASKER CERTIFIED SOLUTION
timbrigham

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question
Keith Alabaster

Yes - surprised me too, haven't got an answer for the moment.
timbrigham

ASKER
Keith, could you act and verify if the key lifetime in the IP Security Monitor->Main Mode->Security Associations matches the phase 1 key generation time? The tech I've been working with hasn't addressed those values not matching and I'd like to know what they are in a working environment.
timbrigham

ASKER
After a long and arduous argument we finally have a couple senior techs looking at this in a lab. They are treating it as a product defect.
Get an unlimited membership to EE for less than $4 a week.
Unlimited question asking, solutions, articles and more.