[strongSwan] How to change phase 1 and 2 re-negotiation time?
Andreas Steffen
andreas.steffen at strongswan.org
Mon Jan 2 23:24:34 CET 2012
Hi Meera,
please have a look at our rekeying HOWTO:
http://wiki.strongswan.org/projects/strongswan/wiki/ExpiryRekey
Best regards
Andreas
On 02.01.2012 10:43, Meera Sudhakar wrote:
> Hi,
>
> Happy New Year to all at the strongSwan team!
>
> I have a couple of queries regarding ipsec.conf parameters:
>
> 1) How can I change the re-negotiation time of phase 1 and phase 2? Are
> there any parameters I can include in ipsec.conf? Also, should these
> parameters be used in the config files at both end-points?
>
> 2) Could you please explain the parameter "keylife" to me? From what I
> know, it determines how long a particular SA should be active (time
> between creation and expiration). But re-negotiation happens before
> expiration can take place. Please let me know if this is correct or wrong.
>
> Thanks and regards,
> Meera
======================================================================
Andreas Steffen andreas.steffen at strongswan.org
strongSwan - the Linux VPN Solution! www.strongswan.org
Institute for Internet Technologies and Applications
University of Applied Sciences Rapperswil
CH-8640 Rapperswil (Switzerland)
===========================================================[ITA-HSR]==
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4489 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://lists.strongswan.org/pipermail/users/attachments/20120102/8f377225/attachment.bin>
More information about the Users
mailing list