Re: [strongSwan] best practice for IKEv2 lifetimes

2018-03-23 Thread Waldemar Brodkorb
Hi Noel, Noel Kuntze wrote, > Hi, > > Set the correct life time locally and a sizeable margintime. > That works around the issue of bad administration on the other end. If they > set it up right, the lifetime is exactly the same as on your side, the > margintime makes a collision unlikely. >

Re: [strongSwan] best practice for IKEv2 lifetimes

2018-03-08 Thread Noel Kuntze
Hi, Set the correct life time locally and a sizeable margintime. That works around the issue of bad administration on the other end. If they set it up right, the lifetime is exactly the same as on your side, the margintime makes a collision unlikely. If the lifetime on your side is less than on

[strongSwan] best practice for IKEv2 lifetimes

2018-03-07 Thread Waldemar Brodkorb
Hi, We are using Strongswan 5.5.1 on Debian 9 with IKEv2. The other sides are Cisco ISR 2900 routers. The connection works fine, but sometimes we have a disconnect and the tunnels on the Cisco side marked as down. After /etc/init.d/ipsec restart everything works again. In the early days when I