300-730 · Question #183
What is the default rekey timer for security association pair in the case of IPsec for Cisco ASA?
The correct answer is D. 24 hours. On Cisco ASA, the default IKE Phase 1 (ISAKMP) security association lifetime is 86,400 seconds, which equals 24 hours. When this timer expires, the IKE SA must be renegotiated (rekeyed). This is distinct from the IPsec Phase 2 SA lifetime, which defaults to 28,800 seconds (8 hour
Question
Options
- A8 hours
- B12 hours
- C18 hours
- D24 hours
How the community answered
(23 responses)- B4% (1)
- D96% (22)
Explanation
On Cisco ASA, the default IKE Phase 1 (ISAKMP) security association lifetime is 86,400 seconds, which equals 24 hours. When this timer expires, the IKE SA must be renegotiated (rekeyed). This is distinct from the IPsec Phase 2 SA lifetime, which defaults to 28,800 seconds (8 hours) on ASA. The question refers to the SA pair lifetime in the context of the IKE/ISAKMP negotiation, so the correct default is 24 hours. You can verify or change this on ASA with the command isakmp policy <priority> lifetime <seconds> or in IKEv2 policy configuration.
Topics
Community Discussion
No community discussion yet for this question.