[strongSwan] How to change phase 1 and 2 re-negotiation time?

Andreas Steffen andreas.steffen at strongswan.org
Mon Jan 2 23:24:34 CET 2012


Hi Meera,

please have a look at our rekeying HOWTO:

http://wiki.strongswan.org/projects/strongswan/wiki/ExpiryRekey

Best regards

Andreas

On 02.01.2012 10:43, Meera Sudhakar wrote:
> Hi,
>  
> Happy New Year to all at the strongSwan team!
>  
> I have a couple of queries regarding ipsec.conf parameters:
>  
> 1) How can I change the re-negotiation time of phase 1 and phase 2? Are
> there any parameters I can include in ipsec.conf? Also, should these
> parameters be used in the config files at both end-points?
>  
> 2) Could you please explain the parameter "keylife" to me? From what I
> know, it determines how long a particular SA should be active (time
> between creation and expiration). But re-negotiation happens before
> expiration can take place. Please let me know if this is correct or wrong.
>  
> Thanks and regards,
> Meera

======================================================================
Andreas Steffen                         andreas.steffen at strongswan.org
strongSwan - the Linux VPN Solution!                www.strongswan.org
Institute for Internet Technologies and Applications
University of Applied Sciences Rapperswil
CH-8640 Rapperswil (Switzerland)
===========================================================[ITA-HSR]==

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4489 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://lists.strongswan.org/pipermail/users/attachments/20120102/8f377225/attachment.bin>


More information about the Users mailing list