- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Hi Checkmates,
Can you help me how to configure the tunnel expiration on the capture have 1 hour and what the purpose off the tunnel created and tunnel expiration?
[Expert@Internal-GW:0]# vpn tu tlist
+-----------------------------------------+-----------------------+---------------------+
| Peer: 172.16.10.1 (cd6b8f0973d32146) | MSA: ffffc9001f624410 | i: 0 ref: -- 45/60 |
| Client public IP: 203.0.113.200 | | i: 1 ref: 4 |
| Authenticated at: Apr 11 01:36:22 | | i: 2 ref: -- 46/60 |
| Methods: ESP Tunnel 3DES SHA1 | | |
| My TS: 0.0.0.0/0 | | |
| Peer TS: 172.16.10.1 | | |
| User: test | | |
| MSPI: 800005 (i: 1, p: 0) | Out SPI: 6980210e | |
| Tunnel created: Apr 11 01:36:22 | NAT-T | |
| Tunnel expiration: Apr 11 02:36:22 | | |
+-----------------------------------------+-----------------------+---------------------+
(0) Site-to-Site tunnels are up:
IPSEC 0
NAT-T 0
(1) Number of Active Clients:
NAT-T 1
Visitor Mode 0
SSL 0
As this is standard, it is the same for all vendors: https://en.wikipedia.org/wiki/Internet_Key_Exchange
Thanks Albrecht,
I have read the SK and confused to read the SK because I cant find mention about tunnel_expiration and tunnel created
I have try on the lab-> using checkmate lab,
I try to find the configuration for tunnel created and tunnel expiration and I try to change the vpn_table.def on SMS(r81.10)
#define ISAKMP_TABLE_TIMEOUT 3600 --> change to 300
#define SPI_TABLE_TIMEOUT 3600 --> change to 300
#define IKE_SA_TABLE_TIMEOUT 3600 -> cahnge to 300
after change, push policy.
but the result is same duration for tunnel still 1 hour.
IKE_SA_table |
|
Thanks Albrecht,
I'm using remote access community, its possible to set the duration tunnel created and tunnel created?
if renegotiation expired what happen with the connection is re-establish?
Every hour, renegotiation of IPsec SA happens.
Thanks ALbrecht,
in the process renegotiation IPsec SA status connection is always establish right? not interrupt the traffic?
can you share the document about renegotiation IPsec SA on CheckPoint.
As this is standard, it is the same for all vendors: https://en.wikipedia.org/wiki/Internet_Key_Exchange
Thanks Albrecht
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 66 | |
| 19 | |
| 13 | |
| 12 | |
| 11 | |
| 9 | |
| 9 | |
| 7 | |
| 7 | |
| 7 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY