1. Palo Alto Networks PAN-OS® Administrator’s Guide 10.2: In the section describing how to set up an IPSec VPN
the configuration of the IPSec Crypto profile is detailed. It explicitly lists "Lifetime" as a configurable parameter for the Phase 2 Security Association.
Reference: Network > Network Profiles > IPSec Crypto > Add IPSec Crypto Profile. The dialog box shows fields for "IPSec Protocol
" "Encryption
" "Authentication
" "DH Group
" and "Lifetime." This directly confirms the lifetime is a Phase 2 parameter set in this profile.
2. Palo Alto Networks PAN-OS® Administrator’s Guide 10.2: The guide explains the role of each component in an IPSec VPN. It differentiates the IKE Crypto profile (Phase 1) from the IPSec Crypto profile (Phase 2).
Reference: Section "Set Up an IPSec VPN
" Step 5: "Add an IPSec Crypto profile to specify the protocols and algorithms for authenticating and encrypting traffic in the IPSec security association (Phase 2)."
3. Palo Alto Networks PAN-OS® Administrator’s Guide 10.2: The guide clarifies the function of the IKE Crypto profile
confirming it is for Phase 1.
Reference: Section "Set Up an IPSec VPN
" Step 4: "Add an IKE Crypto profile to specify the protocols and algorithms for authentication
encryption
and key exchange in the IKE security association (Phase 1)."