<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Crypto Map Dynamic IP Reconnection Issues in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/crypto-map-dynamic-ip-reconnection-issues/m-p/275691#M1060098</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It'll be because the PIX doesn't recognise that the tunnel has gone down, and therefore still tries the old tunnel and nothing works, until you reboot the PIX or clear down the tunnels.  All this does is make the PIX build new tunnels and everything works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to enable ISAKMP keepalives on both ends so that they'll determine that the other end has gone down and reset their own tunnels, allowing new ones to be built.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Use:&lt;/P&gt;&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;crypto isakmp keepalive 30&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;on the router, and:&lt;/P&gt;&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;isakmp keepalive 30&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;on the PIX and they'll send keepalives every 30 seconds then and quickly know if the other end has died.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 21 Apr 2004 00:11:18 GMT</pubDate>
    <dc:creator>gfullage</dc:creator>
    <dc:date>2004-04-21T00:11:18Z</dc:date>
    <item>
      <title>Crypto Map Dynamic IP Reconnection Issues</title>
      <link>https://community.cisco.com/t5/network-security/crypto-map-dynamic-ip-reconnection-issues/m-p/275690#M1060095</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are connecting using at each remote site a Cisco 837 router with a ISDN modem as a passthrough to a PIX Firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Each time the ISDN connection drops the Cisco box either requires a reboot or the crypto map to be restarted before anyone can connect through to the PIX.  Has anyone got any ideas please?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:21:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/crypto-map-dynamic-ip-reconnection-issues/m-p/275690#M1060095</guid>
      <dc:creator>mh144831</dc:creator>
      <dc:date>2020-02-21T07:21:09Z</dc:date>
    </item>
    <item>
      <title>Re: Crypto Map Dynamic IP Reconnection Issues</title>
      <link>https://community.cisco.com/t5/network-security/crypto-map-dynamic-ip-reconnection-issues/m-p/275691#M1060098</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It'll be because the PIX doesn't recognise that the tunnel has gone down, and therefore still tries the old tunnel and nothing works, until you reboot the PIX or clear down the tunnels.  All this does is make the PIX build new tunnels and everything works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to enable ISAKMP keepalives on both ends so that they'll determine that the other end has gone down and reset their own tunnels, allowing new ones to be built.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Use:&lt;/P&gt;&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;crypto isakmp keepalive 30&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;on the router, and:&lt;/P&gt;&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;isakmp keepalive 30&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;on the PIX and they'll send keepalives every 30 seconds then and quickly know if the other end has died.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Apr 2004 00:11:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/crypto-map-dynamic-ip-reconnection-issues/m-p/275691#M1060098</guid>
      <dc:creator>gfullage</dc:creator>
      <dc:date>2004-04-21T00:11:18Z</dc:date>
    </item>
  </channel>
</rss>

