cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2413
Views
0
Helpful
2
Replies

ASA IPsec site to site Failover

NETAD
Level 4
Level 4

Hello, I’ve configured a IPsec tunnel between a remote site ASA and a headend ASA. The remote site ASA has 2 Internet circuits so 2 crypto maps tied to each outside interface. The headend ASA has one internet circuit with one crypto map with 2 peers. Failover is configured on the remote ASA via ip sla and tracking. Failover is working correctly and the tunnels are getting established but for the first 15 mins there are consistent flapping and then it stables out. What would be the reason for that? Is there anything I can configure on the headend ASA to flush the dead tunnel? Maybe tunnel keepalives or dead peer detecttion?

2 Replies 2

Hi, enable dpd to clear sa for none responding peer.

**** please remember to rate useful posts

Take a look at this blog post of mine, although it is more focus on how to implement preemption with redundant site-to-site VPN tunnel, but it might be helpful in your scenario:

https://bluenetsec.com/cisco-asa-ipsec-site-to-site-vpn-preemption/

Review Cisco Networking for a $25 gift card