Hi all,
Shall we start this new thread with the looks and feels of XG v18 MR-3?
community.sophos.com/.../xg-firewall-v18-mr3
This thread was automatically locked due to age.
Hi all,
Shall we start this new thread with the looks and feels of XG v18 MR-3?
community.sophos.com/.../xg-firewall-v18-mr3
Hello Argo,
the lifetime of Phase I and Phase II keys cannot be the same. The key life for Phase I is recommended to be at least twice as long as for Phase II.
Personally, I use a lifetime 7800 seconds for Phase I and 3600 seconds for Phase II. It is important that the lifetime for Phase II is not an integer multiple of the lifetime for Phase I. In this case, the multiple is 2.166666666666667.
Try these times and I think the IPsec tunnel will be stable and functional.
The setting for Dead Peer Detection has no effect on the stability of the IPsec tunnel in this case.
Regards
alda
Please open an own thread about your issue and link it here.