--- Begin Message ---
IIRC, if the change you made was global, existing SA's wouldn't use new
replay-window size.
If you want existing-SA's to use new replay-window size, change would be to
individual crypto-map entries.
./Randy
----- Original Message -----
From: Artem Viklenko <[email protected]>
To: [email protected]
Sent: Saturday, May 28, 2016 10:25 AM
Subject: [c-nsp] ASA: IPSec replay window size change
Hi, All!
Having periodic replay window alerts with some customers,
we desides to increase replay window globally to the max
value of 1024 using the command
crypto ipsec security-association replay window-size 1024
But I can't find info how it is affects existing SAs.
I think that new window size will be applied to new SAs.
But what will happen with exising ones. My main concern:
is it non-dusruptive to apply this change on production
firewall?
Thanks in advance!
--
Regards!
_______________________________________________
cisco-nsp mailing list [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/
--- End Message ---
_______________________________________________
cisco-nsp mailing list [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/