<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IPSec VPN with Dual-ISP issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ipsec-vpn-with-dual-isp-issue/m-p/2720988#M193819</link>
    <description>&lt;P&gt;Hello community, how are you?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here I am again, having some issues with a pair of ASA 5505 (Sec Plus).&lt;/P&gt;&lt;P&gt;This the scenario I have:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA-1 ---&amp;gt; Only 1 ISP and LAN interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA-2 ---&amp;gt; 2 ISP (main and secondary) and LAN interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is a VPN to access from LAN to LAN. Dual ISP is configured and working on ASA-2. VPN redundancy as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The VPN failover is working fine, really fine! when I unplug the main ISP cable, secondary comes up and VPN works perfect. And when plug it back, main ISP comes up and VPN works perfect as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue is particularly one and it's related to IP telephony:&lt;/P&gt;&lt;P&gt;We are providing IP phones and PBX services. Client behind ASA-2 (LAN network) have many Polycom IP phones that use SIP (5060) to authenticate against a PBX behind ASA-1 (a third interface called PBX-Net) that has a static NAT to be reachable from internet directly.&lt;/P&gt;&lt;P&gt;So Polycom phones behind ASA-2, have configured the PBX server with a DNS (pointing to the public IP of the ASA-1 static NAT) like "sip123.my-pbx.com" through port UDP/5060.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue comes when Dual-ISP starts working. When I disconnect main ISP, secondary comes up perfectly users can access internet.. BUT... many phones do not reconnect to PBX server. Many other DO. Like 50-50 of the phones register against PBX server. Even tough they were rebooted many times.&lt;/P&gt;&lt;P&gt;Sometimes they keep DNS cached or routes as well so I rebooted them. But nothing.. those Polycom don't even try to reach the PBX server (checking the ASDM real-time I don't see any packet for PBX server).&lt;/P&gt;&lt;P&gt;I also tried "clear arp" and "clar xlate" on both ASA-1 and ASA-2, but nothing.. still not registering.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So.. tired of troubleshooting and finding nothing I got the ASA-2 rebooted.&lt;/P&gt;&lt;P&gt;Magically all the phones came up and I didn't have to reboot them. Is there anything I'm missing? I mean.. something else to clear besides ARP and NAT tables??&lt;/P&gt;&lt;P&gt;I don't explain myself why rebooting works.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I test the PBX service separately with both ISP links it works fine. The issue happens when running the Dual-ISP. Also when plugging back the main ISP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any suggestions??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you people!&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 06:16:01 GMT</pubDate>
    <dc:creator>fborelli07</dc:creator>
    <dc:date>2019-03-12T06:16:01Z</dc:date>
    <item>
      <title>IPSec VPN with Dual-ISP issue</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-with-dual-isp-issue/m-p/2720988#M193819</link>
      <description>&lt;P&gt;Hello community, how are you?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here I am again, having some issues with a pair of ASA 5505 (Sec Plus).&lt;/P&gt;&lt;P&gt;This the scenario I have:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA-1 ---&amp;gt; Only 1 ISP and LAN interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA-2 ---&amp;gt; 2 ISP (main and secondary) and LAN interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is a VPN to access from LAN to LAN. Dual ISP is configured and working on ASA-2. VPN redundancy as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The VPN failover is working fine, really fine! when I unplug the main ISP cable, secondary comes up and VPN works perfect. And when plug it back, main ISP comes up and VPN works perfect as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue is particularly one and it's related to IP telephony:&lt;/P&gt;&lt;P&gt;We are providing IP phones and PBX services. Client behind ASA-2 (LAN network) have many Polycom IP phones that use SIP (5060) to authenticate against a PBX behind ASA-1 (a third interface called PBX-Net) that has a static NAT to be reachable from internet directly.&lt;/P&gt;&lt;P&gt;So Polycom phones behind ASA-2, have configured the PBX server with a DNS (pointing to the public IP of the ASA-1 static NAT) like "sip123.my-pbx.com" through port UDP/5060.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue comes when Dual-ISP starts working. When I disconnect main ISP, secondary comes up perfectly users can access internet.. BUT... many phones do not reconnect to PBX server. Many other DO. Like 50-50 of the phones register against PBX server. Even tough they were rebooted many times.&lt;/P&gt;&lt;P&gt;Sometimes they keep DNS cached or routes as well so I rebooted them. But nothing.. those Polycom don't even try to reach the PBX server (checking the ASDM real-time I don't see any packet for PBX server).&lt;/P&gt;&lt;P&gt;I also tried "clear arp" and "clar xlate" on both ASA-1 and ASA-2, but nothing.. still not registering.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So.. tired of troubleshooting and finding nothing I got the ASA-2 rebooted.&lt;/P&gt;&lt;P&gt;Magically all the phones came up and I didn't have to reboot them. Is there anything I'm missing? I mean.. something else to clear besides ARP and NAT tables??&lt;/P&gt;&lt;P&gt;I don't explain myself why rebooting works.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I test the PBX service separately with both ISP links it works fine. The issue happens when running the Dual-ISP. Also when plugging back the main ISP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any suggestions??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you people!&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:16:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-with-dual-isp-issue/m-p/2720988#M193819</guid>
      <dc:creator>fborelli07</dc:creator>
      <dc:date>2019-03-12T06:16:01Z</dc:date>
    </item>
    <item>
      <title>People,Right after finishing</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-with-dual-isp-issue/m-p/2720989#M193820</link>
      <description>&lt;P&gt;People,&lt;/P&gt;&lt;P&gt;Right after finishing the post, I saw that maybe the problem is the UDP timeout for connections.&lt;/P&gt;&lt;P&gt;It's related to command: "timeout floating-conn".&lt;/P&gt;&lt;P&gt;When multiple static routes exist to a network with different metrics, the ASA uses the one with the best metric at the time of connection creation. If a better route becomes available, then this timeout lets connections be closed so a connection can be reestablished to use the better route. The default is 0 (the connection never times out).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I'm going to change it to 0:0:30 (30 seconds) and let you all know!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2015 00:02:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-with-dual-isp-issue/m-p/2720989#M193820</guid>
      <dc:creator>fborelli07</dc:creator>
      <dc:date>2015-07-15T00:02:36Z</dc:date>
    </item>
  </channel>
</rss>

