IPsec Rekey Timer for a 24-Hour OMP Graceful Restart?

Answer Correct answer: D — Set the IPsec rekey timer to 48 hours, at least twice the 24-hour OMP graceful restart interval.

Which value of the IPsec rekey timer must be set by the engineer for an OMP graceful restart value set for 24 hours?

  1. 6 hours
  2. 12 hours
  3. 36 hours
  4. 48 hours Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests the 2x relationship between the IPsec rekey timer and the OMP graceful restart timer; the trap is choosing the same value as the graceful restart interval (24 hours) or the default rekey value instead of doubling it.

In Cisco SD-WAN the IPsec rekey timer must be at least twice the OMP graceful restart interval, so a 24-hour graceful restart requires a 48-hour rekey timer. This page confirms that 48 hours (D) is the correct value and explains why values below 2x are wrong.

The most common wrong pick is 12 hours, because learners either treat the 12-hour default OMP graceful restart value as the answer or assume the rekey timer only needs to match, not exceed, the restart window.

Community Discussion (3 comments)

2e6bc5f 👍 1 Selected: D
In Cisco SD-WAN, when setting the OMP graceful restart timer, the IPsec rekey timer must be set to at least twice the OMP graceful restart interval. • OMP graceful restart = 24 hours • Required IPsec rekey timer = 2 × 24 = 48 hours This ensures that IPsec tunnels remain valid long enough during the OMP restart window to prevent tunnel teardown.
jhgt2000 👍 1 Selected: D
https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/security/ios-xe-17/security-book-xe/configure-security-param.html
jawad_khalife 👍 1 Selected: D
The default OMP graceful restart value is 12 hours and can be set to a maximum of 604,800 seconds, which is equivalent to 7 days. The IPsec rekey timer is set to 24 hours by default, and although both timers are configurable, the IPsec rekey timer must be at least two times the value of the OMP graceful restart timer. https://rafaesil.medium.com/ccie-ep-16-def-sd-wan-self-efficiency-experience-sec-65c6d4412733#:~:text=The%20default%20OMP%20graceful%20restart,the%20OMP%20graceful%20restart%20timer. Answer shold be D

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Cisco SD-WAN requires the IPsec rekey timer to be at least two times the OMP graceful restart interval, so tunnels stay valid for the entire OMP restart window instead of being torn down mid-restart. With an OMP graceful restart value of 24 hours, the minimum compliant rekey timer is 2 × 24 = 48 hours, which matches option D exactly. One voter (2e6bc5f) summarized the rule plainly: the rekey timer must be set to "at least twice the OMP graceful restart interval," yielding "2 × 24 = 48 hours." Any smaller value would let the IPsec SA expire while OMP is still restarting, defeating the purpose of graceful restart.

Why the Other Options Are Wrong

6 hours is far below the doubling requirement and would expire four times over during the 24-hour restart window. 12 hours is a distractor drawn from the default OMP graceful restart value (as jawad_khalife noted, the default is 12 hours and can be raised up to 604,800 seconds, about 7 days) rather than the rekey timer calculation. 36 hours is closer but still only 1.5× the restart interval, so it violates the at-least-2x rule. Only 48 hours satisfies the 2× relationship for a 24-hour graceful restart.

Community Comment Notes

All votes in the thread converged on D, and the reasoning is consistent with Cisco's documentation rather than mere majority pressure. One commenter (jhgt2000) supplied the Cisco security configuration parameter guide link confirming the timers are related and must be sized together. Another (jawad_khalife) added useful default context: the IPsec rekey timer defaults to 24 hours, and while both timers are configurable, the rekey timer must remain at least twice the OMP graceful restart value. Taken together, the comments describe the exact multiplication rule that makes 48 hours the only compliant answer.

Official Reference

Exam Strategy

Whenever a scenario pairs the IPsec rekey timer with OMP graceful restart, immediately double the graceful restart value and check whether it is within the allowed maximum. If the doubled result exceeds the rekey timer limit, the graceful restart value must be lowered instead.

Frequently Asked Questions

Why must the IPsec rekey timer be twice the OMP graceful restart value?

The IPsec SA must outlive the entire OMP restart window so tunnels are not torn down while OMP is recovering; doubling the restart interval guarantees the SA stays valid.

Is 36 hours valid for a 24-hour OMP graceful restart in Cisco SD-WAN?

No. 36 hours is only 1.5× the restart interval, and the rekey timer must be at least 2× that value, so 48 hours is the minimum valid setting.

Related Analysis

Practice All 300-415 Questions

Access 120 questions with complete answers and detailed explanations.

View Full 300-415 Practice Test →

← Back to 300-415 Study Guide