ikev2 rekey intervals[SOLVED]

Hi All:

In the Digi transports, the IKEv2 setup there these two entries:
Renegotiate after  hrs  mins  secs
Rekey after  hrs  mins  secs

Which one should be the bigger of the two?

Renegotiate to me means the entire renegotiation of the original IKE whereas the rekey to me means just rekeying the CILD_SA.
So the rekey should be shorted than the renegotiation.

Do I have that correct?


Hi John,
Yes, the rekey is the CHILD_SA, this should be the shorter lifetime.
Ben @ Digi support