ATP500 and rekey time in phase1 for ipsec VPN tunnels

TasagoreSeibei
TasagoreSeibei Posts: 2  Freshman Member

Hi

I have a IPSEC tunnel, the other side is a Sophos device. We have intermittent disconnections and the Sophos guy says that it's due a bad rekey time. The remote log shows:

"Received IKE message with invalid SPI"

They have the tunnel configured in Phase1 for SA LifeTime of 10800s with a re-key margin of 360s, but I can't configure the second one setting in the ATP500.

Which is the default re-key margin for an ATP500?

Regards

All Replies

  • Zyxel_Judy
    Zyxel_Judy Posts: 1,879  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security Zyxel Certified Network Engineer Level 1 - Nebula

    Hi @TasagoreSeibei ,

    They have the tunnel configured in Phase1 for SA LifeTime of 10800s with a re-key margin of 360s, but I can't configure the second one setting in the ATP500.

    Which is the default re-key margin for an ATP500?

    Let me clarify what you're asking:

    • For the Sophos device: They can set Phase 1 SA Lifetime of 10800s with a 360s re-key margin.
    • For the ATP500: You can only set Phase 1 SA Lifetime, but no re-key margin setting is available? Are you looking to confirm what the default re-key margin is for Phase 1 on the ATP500?