Does anyone know how to change the default value of vpn-idle-timeout 30 on Cisco FMC or Cisco FTD CLI. I have just configured a site-to-site VPN and it goes down every 30 mins on Cisco FMC.
I have checked almost everywhere on the Internet, don't know why it's so difficult on Cisco FTD but easy on Cisco ASA.
Are you facing this issue continuously even when the L2L session is active...???
I couldn't find any direct way to change the idle timeout value in FTD. Did you try by changing this with FLEX CONFIG.
First, vpn-idle-timeout should only take effect if there is no traffic on the site-site VPN for the specified period.
Flexconfig is the correct place to change this parameter (as of 6.5 at least).
If you've verified that you have it set (double check that you are using the expected group-policy) and you are still seeing timeouts even though you have not met your specified idle timeout value, it may be happening due to a setting on the remote end.
With no traffic we would expect the tunnel to tear down after 30 minutes. That's normal behavior and by design.
As long as there is traffic, it would normally rekey before the lifetime expires and stay up effectively forever.