[strongSwan] How to change phase 1 and 2 re-negotiation time?

Meera Sudhakar mira.sudhakar at gmail.com
Mon Jan 2 10:43:36 CET 2012


Happy New Year to all at the strongSwan team!

I have a couple of queries regarding ipsec.conf parameters:

1) How can I change the re-negotiation time of phase 1 and phase 2? Are
there any parameters I can include in ipsec.conf? Also, should these
parameters be used in the config files at both end-points?

2) Could you please explain the parameter "keylife" to me? From what I
know, it determines how long a particular SA should be active (time between
creation and expiration). But re-negotiation happens before expiration can
take place. Please let me know if this is correct or wrong.

Thanks and regards,
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.strongswan.org/pipermail/users/attachments/20120102/3081a755/attachment.html>

More information about the Users mailing list