Quantcast
Channel: All ScreenOS Firewalls (NOT SRX) posts
Viewing all articles
Browse latest Browse all 2577

Re: No VPN Traffic Flows for 3 Minutes after Phase 2 ReKey

$
0
0

Both NS5GT's are running 5.0.0r11.1

 

The IKE parameters look like they are default:

 

Florida 10.0.1.1

ns5gtFL-> get ike soft-lifetime-buffer

IPsec Soft Lifetime Buffer is 10 seconds

ns5gtFL-> get ike initiator-set-commit

Commit bit will not be set when initiate phase 2 session.

ns5gtFL-> get ike responder-set-commit

Commit bit will be not set when respond to phase 2 session.

 

California 10.0.0.1

ns5gt-> get ike soft-lifetime-buffer

IPsec Soft Lifetime Buffer is 10 seconds

ns5gt-> get ike initiator-set-commit

Commit bit will not be set when initiate phase 2 session.

ns5gt-> get ike responder-set-commit

Commit bit will be not set when respond to phase 2 session

 

We will get the debug flow tomorrow afternoon while traffic is not flowing.


Viewing all articles
Browse latest Browse all 2577

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>