Update Networking/Sophos/IPSec Site-to-Site VPN Tunnel.md
This commit is contained in:
@ -57,15 +57,15 @@ Navigate to "**System > Profiles > IPSec Profiles > Custom_IKEv2_`<Initiator>/<R
|
|||||||
|
|
||||||
| **Field** | **Value** | **Notes** |
|
| **Field** | **Value** | **Notes** |
|
||||||
| :--- | :--- | :--- |
|
| :--- | :--- | :--- |
|
||||||
| Phase 1 Lifetime | `<Longer Lifetime Compared to Phase 2>` | *Default Value*: `28800` |
|
| Phase 1 Lifetime | *Default Value*: `28800` | `<Longer Lifetime Compared to Phase 2>` |
|
||||||
| Phase 2 Lifetime | `<Shorter Lifetime Compared to Phase 1>` | *Default Value*: `14400` |
|
| Phase 2 Lifetime | *Default Value*: `14400` | `<Shorter Lifetime Compared to Phase 1>` |
|
||||||
|
|
||||||
=== "Responder Phase Lifetime Values"
|
=== "Responder Phase Lifetime Values"
|
||||||
|
|
||||||
| **Field** | **Value** | **Notes** |
|
| **Field** | **Value** | **Notes** |
|
||||||
| :--- | :--- | :--- |
|
| :--- | :--- | :--- |
|
||||||
| Phase 1 Lifetime | `<Longer Lifetime Compared to Phase 2>` | *Default Value + 300 Seconds*: `328800` |
|
| Phase 1 Lifetime | *Default Value + 300 Seconds*: `328800` | `<Longer Lifetime Compared to Phase 2>` |
|
||||||
| Phase 2 Lifetime | `<Shorter Lifetime Compared to Phase 1>` | *Default Value + 300 Seconds*: `314400` |
|
| Phase 2 Lifetime | *Default Value + 300 Seconds*: `314400` | `<Shorter Lifetime Compared to Phase 1>` |
|
||||||
|
|
||||||
!!! warning "Remote / Local Phase Lifetimes"
|
!!! warning "Remote / Local Phase Lifetimes"
|
||||||
Within the context of the remote and local VPN tunnels, the lifetime of the Phase 1 and Phase 2 encryption keys needs to be shorter on the intiator than the responder sides of the VPN tunnel.
|
Within the context of the remote and local VPN tunnels, the lifetime of the Phase 1 and Phase 2 encryption keys needs to be shorter on the intiator than the responder sides of the VPN tunnel.
|
||||||
|
Reference in New Issue
Block a user