nerdexam
Cisco

300-730 · Question #183

What is the default rekey timer for security association pair in the case of IPsec for Cisco ASA?

The correct answer is D. 24 hours. On Cisco ASA, the default IKE Phase 1 (ISAKMP) security association lifetime is 86,400 seconds, which equals 24 hours. When this timer expires, the IKE SA must be renegotiated (rekeyed). This is distinct from the IPsec Phase 2 SA lifetime, which defaults to 28,800 seconds (8 hour

Site-to-site VPNs on Routers and Firewalls

Question

What is the default rekey timer for security association pair in the case of IPsec for Cisco ASA?

Options

  • A8 hours
  • B12 hours
  • C18 hours
  • D24 hours

How the community answered

(23 responses)
  • B
    4% (1)
  • D
    96% (22)

Explanation

On Cisco ASA, the default IKE Phase 1 (ISAKMP) security association lifetime is 86,400 seconds, which equals 24 hours. When this timer expires, the IKE SA must be renegotiated (rekeyed). This is distinct from the IPsec Phase 2 SA lifetime, which defaults to 28,800 seconds (8 hours) on ASA. The question refers to the SA pair lifetime in the context of the IKE/ISAKMP negotiation, so the correct default is 24 hours. You can verify or change this on ASA with the command isakmp policy <priority> lifetime <seconds> or in IKEv2 policy configuration.

Topics

#IPsec SA#rekey timer#Cisco ASA#security association

Community Discussion

No community discussion yet for this question.

Full 300-730 Practice