IPSec/racoon key time to live

2010-10-14 Thread Erik Norgaard
Hi: I'm up against configuring a number of different systems with host-host IPSec AH-only. The systems use different versions of racoon. Questions: - Must the key lifetime be the same in both ends? - Can key lifetime be configured per host-host connection? Thanks, Erik -- Erik Nørgaard

Re: IPSec/racoon key time to live

2010-10-14 Thread Jerome Herman
Le 14/10/2010 16:26, Erik Norgaard a écrit : Hi: I'm up against configuring a number of different systems with host-host IPSec AH-only. The systems use different versions of racoon. Questions: - Must the key lifetime be the same in both ends? In theory both ends are supposed to negotiate