Quantcast
Channel: All SRX Services Gateway posts
Viewing all articles
Browse latest Browse all 17645

Re: VPN Rekeying process.

$
0
0

Rekeying should not interrupt traffic. There are two timers for every IPSEC SA pair. Soft and hard. Hard timer is the lifetime-seconds parameter you configure under ipsec proposal. By default 3600s. Soft timer is more or less 5/6 of the hard timer. When the soft timer expires rekeying process starts and new pair of SAs is negotiated. So for some period of time there are 4 SAs. Up to 10.4 old SAs were kept until hard timer expired. From 11.4 they are marked as expired just after new pair is negotiated.

 

https://kb.juniper.net/InfoCenter/index?page=content&id=KB19835

https://kb.juniper.net/InfoCenter/index?page=content&id=KB26692


Viewing all articles
Browse latest Browse all 17645

Trending Articles