IPsec Rekey Timer for a 24-Hour OMP Graceful Restart?
Which value of the IPsec rekey timer must be set by the engineer for an OMP graceful restart value set for 24 hours?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests the 2x relationship between the IPsec rekey timer and the OMP graceful restart timer; the trap is choosing the same value as the graceful restart interval (24 hours) or the default rekey value instead of doubling it.
In Cisco SD-WAN the IPsec rekey timer must be at least twice the OMP graceful restart interval, so a 24-hour graceful restart requires a 48-hour rekey timer. This page confirms that 48 hours (D) is the correct value and explains why values below 2x are wrong.
The most common wrong pick is 12 hours, because learners either treat the 12-hour default OMP graceful restart value as the answer or assume the rekey timer only needs to match, not exceed, the restart window.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Cisco SD-WAN requires the IPsec rekey timer to be at least two times the OMP graceful restart interval, so tunnels stay valid for the entire OMP restart window instead of being torn down mid-restart. With an OMP graceful restart value of 24 hours, the minimum compliant rekey timer is 2 × 24 = 48 hours, which matches option D exactly. One voter (2e6bc5f) summarized the rule plainly: the rekey timer must be set to "at least twice the OMP graceful restart interval," yielding "2 × 24 = 48 hours." Any smaller value would let the IPsec SA expire while OMP is still restarting, defeating the purpose of graceful restart.Why the Other Options Are Wrong
6 hours is far below the doubling requirement and would expire four times over during the 24-hour restart window. 12 hours is a distractor drawn from the default OMP graceful restart value (as jawad_khalife noted, the default is 12 hours and can be raised up to 604,800 seconds, about 7 days) rather than the rekey timer calculation. 36 hours is closer but still only 1.5× the restart interval, so it violates the at-least-2x rule. Only 48 hours satisfies the 2× relationship for a 24-hour graceful restart.Community Comment Notes
All votes in the thread converged on D, and the reasoning is consistent with Cisco's documentation rather than mere majority pressure. One commenter (jhgt2000) supplied the Cisco security configuration parameter guide link confirming the timers are related and must be sized together. Another (jawad_khalife) added useful default context: the IPsec rekey timer defaults to 24 hours, and while both timers are configurable, the rekey timer must remain at least twice the OMP graceful restart value. Taken together, the comments describe the exact multiplication rule that makes 48 hours the only compliant answer.Official Reference
Exam Strategy
Whenever a scenario pairs the IPsec rekey timer with OMP graceful restart, immediately double the graceful restart value and check whether it is within the allowed maximum. If the doubled result exceeds the rekey timer limit, the graceful restart value must be lowered instead.
Frequently Asked Questions
Why must the IPsec rekey timer be twice the OMP graceful restart value?
The IPsec SA must outlive the entire OMP restart window so tunnels are not torn down while OMP is recovering; doubling the restart interval guarantees the SA stays valid.
Is 36 hours valid for a 24-hour OMP graceful restart in Cisco SD-WAN?
No. 36 hours is only 1.5× the restart interval, and the rekey timer must be at least 2× that value, so 48 hours is the minimum valid setting.
Related Analysis
Practice All 300-415 Questions
Access 120 questions with complete answers and detailed explanations.
View Full 300-415 Practice Test →