Hi,<br><br> I had seen soft lifetime as 0 in SAD database and when this can happen? can some one please comment. Following are the lifetime and margin values used in our configuration.<br><br>ikelifetime (phase1) : 3600s<br>
keylife (pahse2) : 1800s<br>
rekeymargin : keylifetime/10 = 1800/10<br>rekeyfuzz : 100%<br clear="all"><br><br>Setkey -D<br>====================<br># setkey -D <br>source=10.69.211.113 destination=10.69.211.169 <br>
protocol=esp mode=tunnel spi=171795725(0x0a3d650d) reqid=3(0x00000003) <br> encr-algo=aes-cbc <br> encr-key=d4ce82ab1a1a227042f7223be73992aa <br> auth-algo=hmac-sha1 <br> auth-key=9813fe27b461ae4e21aa30b3c8d4d0d5e02e5beb <br>
replay-window=32 flags=0x11000000 state=mature seq=1 pid=12331 <br> created=2012-03-30/12:59:04 current=2012-03-30/13:20:49 elapsed=1305(s) <br> hard-lifetime=1800(s) expiration=2012-03-30/13:29:04 <br>
<b> soft-lifetime=0(s) renewal=2012-03-30/12:59:04 </b><br> last-use=2012-03-30/12:59:05 <br> bytes-processed=3005251 hard-lifebyte=0 soft-lifebyte=0 <br> vrfid=0 xvrfid=0 <br>source=10.69.211.169 destination=10.69.211.113 <br>
protocol=esp mode=tunnel spi=3393626443(0xca46a14b) reqid=3(0x00000003) <br> encr-algo=aes-cbc <br> encr-key=33df05abedf86b9a83a66e4f4cb47058 <br> auth-algo=hmac-sha1 <br> auth-key=bbaa5769f326304efe20cfb978074f1252e09f18 <br>
replay-window=32 flags=0x10000000 state=mature seq=0 pid=12331 <br> created=2012-03-30/12:59:04 current=2012-03-30/13:20:49 elapsed=1305(s) <br> hard-lifetime=1800(s) expiration=2012-03-30/13:29:04 <br>
soft-lifetime=1557(s) renewal=2012-03-30/13:25:01 <br> last-use=never <br> bytes-processed=2222776 hard-lifebyte=0 soft-lifebyte=0 <br> vrfid=0 xvrfid=0 <br><br><br>-- <br><div> </div>
<div>Regards,</div>
<div>Reshma</div><br>