Make Before Break - Which Firewalls Support it
I run PFSense and have always been worried about enabling make-before-break on IKEV2 IPSEC VPN's as the warning is that the other endpoint must support it otherwise there could be issues.
I do not generally control the other side of the VPN and would like to use this feature but it's hard to judge if the other side does support it, looking for make-before-break details on Google for Palo Alto or Checkpoint doesn't yield any results, are these firewalls using different terminology?
If anyone has any detail or can point me at the terminology to google that would be fantastic.
I'm not aware of any list, but if you are using IKEv2, you are better off switching to Rekey instead of using Reauth+Make-before-break. On 2.4.x, uncheck Disable Rekey and check Disable Reauth. On 2.5.0, put the lifetime value in the rekey box and leave reauth empty.