<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSEC Site-to-Site Tunnel drops every 1hour in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ipsec-site-to-site-tunnel-drops-every-1hour/m-p/857585#M974122</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;does my Global Timeouts set on the connection to 1hr had anything to do with the tunnel drops?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"timeout conn 1:00:00"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 02 Oct 2007 21:49:54 GMT</pubDate>
    <dc:creator>brianbono</dc:creator>
    <dc:date>2007-10-02T21:49:54Z</dc:date>
    <item>
      <title>IPSEC Site-to-Site Tunnel drops every 1hour</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-site-to-site-tunnel-drops-every-1hour/m-p/857580#M974115</link>
      <description>&lt;P&gt;hi guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;need help on my ASA 5510 that establishes a  site-to-site VPN tunnel to a Multitech Firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The tunnel normally drops after an hour of connectivity and would reconnect automatically. The problem is I have a telnet application that connects to the other end of the tunnel that would end up also getting disconnected. If i do a consistent ping to a remote host on the other side of the VPN tunnel i would also get one "request timeout" when the tunnel drops.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;below is my vpn config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;crypto map outside_ISP_map 1 match address outside_ISP_1_cryptomap&lt;/P&gt;&lt;P&gt;crypto map outside_ISP_map 1 set peer 207.224.XXX.XXX&lt;/P&gt;&lt;P&gt;crypto map outside_ISP_map 1 set transform-set ESP-3DES-MD5&lt;/P&gt;&lt;P&gt;crypto map outside_ISP_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO&lt;/P&gt;&lt;P&gt;_MAP&lt;/P&gt;&lt;P&gt;crypto map outside_ISP_map interface outside_ISP&lt;/P&gt;&lt;P&gt;crypto isakmp identity address&lt;/P&gt;&lt;P&gt;crypto isakmp enable outside_ISP&lt;/P&gt;&lt;P&gt;crypto isakmp policy 10&lt;/P&gt;&lt;P&gt; authentication pre-share&lt;/P&gt;&lt;P&gt; encryption 3des&lt;/P&gt;&lt;P&gt; hash md5&lt;/P&gt;&lt;P&gt; group 2&lt;/P&gt;&lt;P&gt; lifetime 86400&lt;/P&gt;&lt;P&gt;no crypto isakmp nat-traversal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;attached also is a screenshot of the Real-Time Log Viewer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:19:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-site-to-site-tunnel-drops-every-1hour/m-p/857580#M974115</guid>
      <dc:creator>brianbono</dc:creator>
      <dc:date>2019-03-11T11:19:04Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC Site-to-Site Tunnel drops every 1hour</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-site-to-site-tunnel-drops-every-1hour/m-p/857581#M974116</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;additional info:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asa001# sh isakmp sa detail&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   Active SA: 1&lt;/P&gt;&lt;P&gt;    Rekey SA: 0 (A tunnel will report 1 Active and 1 Rekey SA during rekey)&lt;/P&gt;&lt;P&gt;Total IKE SA: 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1   IKE Peer: 207.224.xxx.xxx&lt;/P&gt;&lt;P&gt;    Type    : L2L             Role    : initiator&lt;/P&gt;&lt;P&gt;    Rekey   : no              State   : MM_ACTIVE&lt;/P&gt;&lt;P&gt;    Encrypt : 3des            Hash    : MD5&lt;/P&gt;&lt;P&gt;    Auth    : preshared       Lifetime: 86400&lt;/P&gt;&lt;P&gt;    Lifetime Remaining: 82985&lt;/P&gt;&lt;P&gt;asa001# sh isakmp stats&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Global IKE Statistics&lt;/P&gt;&lt;P&gt;Active Tunnels: 1&lt;/P&gt;&lt;P&gt;Previous Tunnels: 668&lt;/P&gt;&lt;P&gt;In Octets: 919211&lt;/P&gt;&lt;P&gt;In Packets: 7753&lt;/P&gt;&lt;P&gt;In Drop Packets: 2241&lt;/P&gt;&lt;P&gt;In Notifys: 1342&lt;/P&gt;&lt;P&gt;In P2 Exchanges: 830&lt;/P&gt;&lt;P&gt;In P2 Exchange Invalids: 0&lt;/P&gt;&lt;P&gt;In P2 Exchange Rejects: 0&lt;/P&gt;&lt;P&gt;In P2 Sa Delete Requests: 37&lt;/P&gt;&lt;P&gt;Out Octets: 764348&lt;/P&gt;&lt;P&gt;Out Packets: 6411&lt;/P&gt;&lt;P&gt;Out Drop Packets: 21&lt;/P&gt;&lt;P&gt;Out Notifys: 1584&lt;/P&gt;&lt;P&gt;Out P2 Exchanges: 452&lt;/P&gt;&lt;P&gt;Out P2 Exchange Invalids: 0&lt;/P&gt;&lt;P&gt;Out P2 Exchange Rejects: 0&lt;/P&gt;&lt;P&gt;Out P2 Sa Delete Requests: 1156&lt;/P&gt;&lt;P&gt;Initiator Tunnels: 351&lt;/P&gt;&lt;P&gt;Initiator Fails: 9&lt;/P&gt;&lt;P&gt;Responder Fails: 4&lt;/P&gt;&lt;P&gt;System Capacity Fails: 0&lt;/P&gt;&lt;P&gt;Auth Fails: 2&lt;/P&gt;&lt;P&gt;Decrypt Fails: 0&lt;/P&gt;&lt;P&gt;Hash Valid Fails: 0&lt;/P&gt;&lt;P&gt;No Sa Fails: 0&lt;/P&gt;&lt;P&gt;asa001#&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Oct 2007 04:08:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-site-to-site-tunnel-drops-every-1hour/m-p/857581#M974116</guid>
      <dc:creator>brianbono</dc:creator>
      <dc:date>2007-10-02T04:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC Site-to-Site Tunnel drops every 1hour</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-site-to-site-tunnel-drops-every-1hour/m-p/857582#M974117</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Seems like the remote peer has negotiated a phase 2 liftime of 1 hour (3600 seconds). The default for the ASA is 8 hours (28,800 seconds) and 1 hour  (3600 secs for a Cisco router). Both peers will negotiate the lowest lifetime value.&lt;/P&gt;&lt;P&gt;You'll need to reconfigure the remote peer's phase 2 liftime to match the ASA value of 8 hours, or increase both peer lifetimes, if you wish the tunnel to stay up longer.&lt;/P&gt;&lt;P&gt;"sh crypto ipsec sa" will display the phase 2 remaining sa lifetime.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Oct 2007 13:20:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-site-to-site-tunnel-drops-every-1hour/m-p/857582#M974117</guid>
      <dc:creator>russ</dc:creator>
      <dc:date>2007-10-02T13:20:16Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC Site-to-Site Tunnel drops every 1hour</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-site-to-site-tunnel-drops-every-1hour/m-p/857583#M974118</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the remote peer also has it set to 86400&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Oct 2007 13:27:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-site-to-site-tunnel-drops-every-1hour/m-p/857583#M974118</guid>
      <dc:creator>brianbono</dc:creator>
      <dc:date>2007-10-02T13:27:46Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC Site-to-Site Tunnel drops every 1hour</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-site-to-site-tunnel-drops-every-1hour/m-p/857584#M974120</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you referring to the phase 1 lifetime or phase 2 lifetime value?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Oct 2007 13:33:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-site-to-site-tunnel-drops-every-1hour/m-p/857584#M974120</guid>
      <dc:creator>russ</dc:creator>
      <dc:date>2007-10-02T13:33:18Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC Site-to-Site Tunnel drops every 1hour</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-site-to-site-tunnel-drops-every-1hour/m-p/857585#M974122</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;does my Global Timeouts set on the connection to 1hr had anything to do with the tunnel drops?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"timeout conn 1:00:00"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Oct 2007 21:49:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-site-to-site-tunnel-drops-every-1hour/m-p/857585#M974122</guid>
      <dc:creator>brianbono</dc:creator>
      <dc:date>2007-10-02T21:49:54Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC Site-to-Site Tunnel drops every 1hour</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-site-to-site-tunnel-drops-every-1hour/m-p/857586#M974124</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had a similar issue but my tunnel between PIX to VPN would drop once a day.  It was with the encryption being different. One was 3des and the other was not.  The tunnel would work, but after 18 hours or so, the tunnel would drop.  This happened very often.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Oct 2007 15:14:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-site-to-site-tunnel-drops-every-1hour/m-p/857586#M974124</guid>
      <dc:creator>flopez</dc:creator>
      <dc:date>2007-10-03T15:14:17Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC Site-to-Site Tunnel drops every 1hour</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-site-to-site-tunnel-drops-every-1hour/m-p/857587#M974125</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am also having a similar experience between a PIX and an EdgeWater IAD router.  Tunnel drops every day or two and takes 5-10 minutes to come back up.  I don't have control over the EdgeWater device but would like to setup some kind of logging on my side to see if I can figure out what is going on.  I tried "logging buffered debug" but that gives WAY too much info.  Is there a way that I can have the output of "debug cry" type command go to a buffer to review it once a day or so?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Diego&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Oct 2007 17:02:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-site-to-site-tunnel-drops-every-1hour/m-p/857587#M974125</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2007-10-03T17:02:53Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC Site-to-Site Tunnel drops every 1hour</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-site-to-site-tunnel-drops-every-1hour/m-p/857588#M974126</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was able to solve this problem yesterday. All I did was to go to the remote vpn tab instead of the site-to-site vpn tab of my ASA to configure the Maximum Connect value under the default group policy. The reason for the was my site-to-site inherited that policy that says the tunnel can only be for 1hr and must reconnect in order to keep the tunnel. I have changed the settings now to unlimited and finally my vpn is working fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cheers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Oct 2007 22:23:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-site-to-site-tunnel-drops-every-1hour/m-p/857588#M974126</guid>
      <dc:creator>brianbono</dc:creator>
      <dc:date>2007-10-03T22:23:17Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC Site-to-Site Tunnel drops every 1hour</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-site-to-site-tunnel-drops-every-1hour/m-p/3319913#M974127</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&amp;nbsp;all,&lt;/P&gt;
&lt;P&gt;I have the same problem which has been explained by brianbono but, the difference is that my default group policy max connect time is unlimited. Still facing the disconnection after 1 hour and automatic reconnect (single request time out). What could be causing this issue.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2018 19:32:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-site-to-site-tunnel-drops-every-1hour/m-p/3319913#M974127</guid>
      <dc:creator>elrasheed1</dc:creator>
      <dc:date>2018-01-26T19:32:38Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC Site-to-Site Tunnel drops every 1hour</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-site-to-site-tunnel-drops-every-1hour/m-p/5215610#M1117003</link>
      <description>&lt;P&gt;Hi brian,&lt;/P&gt;&lt;P&gt;Thank you for this. It also fixed my issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 26 Oct 2024 18:30:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-site-to-site-tunnel-drops-every-1hour/m-p/5215610#M1117003</guid>
      <dc:creator>naveen98</dc:creator>
      <dc:date>2024-10-26T18:30:45Z</dc:date>
    </item>
  </channel>
</rss>

