Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Holy
Contributor

IPSec Sito2Site to Cisco

Hello,

 

short Question. We have to do a VPN in 3 days to a Cisco Gateway. we have exchanged our Setting. and they sai for Phase 2 Key Lifetime 4608000 kilobytes / 3600 seconds.

 

Does it mean that i have to choose in my fortigate Phase 2 Propasals for Lifetime "Both" and wrtite the kilobytes values and second or it will be ok if i only put the 3600 for Lifetime?

 

Thank you

NSE 8 

NSE 1 - 7

 

NSE 8 NSE 1 - 7
1 Solution
emnoc
Esteemed Contributor III

What this means they want use to use both ( byte and sec) and whatever happens 1st renew the ipsec-SA. So in your case

 

config vpn ipsec phase2-interface

 

edit  < your phase2 name >

        set keylife-type both <---toggle both here         set keylifekbs 4608000         set keylifeseconds 3600

end

 

 

 

 

 

PCNSE 

NSE 

StrongSwan  

View solution in original post

PCNSE NSE StrongSwan
4 REPLIES 4
emnoc
Esteemed Contributor III

What this means they want use to use both ( byte and sec) and whatever happens 1st renew the ipsec-SA. So in your case

 

config vpn ipsec phase2-interface

 

edit  < your phase2 name >

        set keylife-type both <---toggle both here         set keylifekbs 4608000         set keylifeseconds 3600

end

 

 

 

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Holy

Thank you emnoc. 

 

btw... you wanted to send me some learning material for Fortimal :) i realy need some, because self study is realy hard

 

 

emnoc wrote:

What this means they want use to use both ( byte and sec) and whatever happens 1st renew the ipsec-SA. So in your case

 

config vpn ipsec phase2-interface

 

 

edit  < your phase2 name >

        set keylife-type both <---toggle both here        set keylifekbs 4608000        set keylifeseconds 3600

end

 

 

 

 

NSE 8 

NSE 1 - 7

 

NSE 8 NSE 1 - 7
emnoc
Esteemed Contributor III

Yes when I get done and back at my home station I will find the ppt I told you about.

 

Ken

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Holy

Ok Thank  you :=)

 

emnoc wrote:

Yes when I get done and back at my home station I will find the ppt I told you about.

 

Ken

NSE 8 

NSE 1 - 7

 

NSE 8 NSE 1 - 7
Labels
Top Kudoed Authors