- Products
- Learn
- Local User Groups
- Partners
- More
Introduction to Lakera:
Securing the AI Frontier!
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hi Checkmates,
Can you help me how to configure the tunnel expiration on the capture have 1 hour and what the purpose off the tunnel created and tunnel expiration?
[Expert@Internal-GW:0]# vpn tu tlist
+-----------------------------------------+-----------------------+---------------------+
| Peer: 172.16.10.1 (cd6b8f0973d32146) | MSA: ffffc9001f624410 | i: 0 ref: -- 45/60 |
| Client public IP: 203.0.113.200 | | i: 1 ref: 4 |
| Authenticated at: Apr 11 01:36:22 | | i: 2 ref: -- 46/60 |
| Methods: ESP Tunnel 3DES SHA1 | | |
| My TS: 0.0.0.0/0 | | |
| Peer TS: 172.16.10.1 | | |
| User: test | | |
| MSPI: 800005 (i: 1, p: 0) | Out SPI: 6980210e | |
| Tunnel created: Apr 11 01:36:22 | NAT-T | |
| Tunnel expiration: Apr 11 02:36:22 | | |
+-----------------------------------------+-----------------------+---------------------+
(0) Site-to-Site tunnels are up:
IPSEC 0
NAT-T 0
(1) Number of Active Clients:
NAT-T 1
Visitor Mode 0
SSL 0
As this is standard, it is the same for all vendors: https://en.wikipedia.org/wiki/Internet_Key_Exchange
Thanks Albrecht,
I have read the SK and confused to read the SK because I cant find mention about tunnel_expiration and tunnel created
I have try on the lab-> using checkmate lab,
I try to find the configuration for tunnel created and tunnel expiration and I try to change the vpn_table.def on SMS(r81.10)
#define ISAKMP_TABLE_TIMEOUT 3600 --> change to 300
#define SPI_TABLE_TIMEOUT 3600 --> change to 300
#define IKE_SA_TABLE_TIMEOUT 3600 -> cahnge to 300
after change, push policy.
but the result is same duration for tunnel still 1 hour.
IKE_SA_table |
|
Thanks Albrecht,
I'm using remote access community, its possible to set the duration tunnel created and tunnel created?
if renegotiation expired what happen with the connection is re-establish?
Every hour, renegotiation of IPsec SA happens.
Thanks ALbrecht,
in the process renegotiation IPsec SA status connection is always establish right? not interrupt the traffic?
can you share the document about renegotiation IPsec SA on CheckPoint.
As this is standard, it is the same for all vendors: https://en.wikipedia.org/wiki/Internet_Key_Exchange
Thanks Albrecht
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
14 | |
11 | |
7 | |
6 | |
6 | |
6 | |
6 | |
4 | |
4 | |
4 |
Tue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY