Update Networking/Sophos/IPSec Site-to-Site VPN Tunnel.md

This commit is contained in:
Nicole Rappe
2024-01-26 18:18:03 -07:00
parent 3eee7601f9
commit c6e58260d8

View File

@ -50,8 +50,8 @@ Navigate to "**System > Profiles > IPSec Profiles > Custom_IKEv2_`<Initiator>/<R
| **Field** | **Value** |
| :--- | :--- |
| Phase 1 Lifetime | `<Longer Lifetime Compared to Phase 2>` (*If Initiator*) |
| Phase 2 Lifetime | `<Shorter Lifetime Compared to Phase 1>` (*If Initiator*) |
| Phase 1 Lifetime | `<Longer Lifetime Compared to Phase 2>` (*Default = `28800`*) |
| Phase 2 Lifetime | `<Shorter Lifetime Compared to Phase 1>` (*Default = `14400`*) |
!!! warning "Remote / Local Phase Lifetimes"
Within the context of the remote and local VPN tunnels, the lifetime of the Phase 1 and Phase 2 encryption keys needs to be shorter on the intiator than the responder sides of the VPN tunnel.