cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
566
Views
0
Helpful
2
Replies

ASA VPN issues for some tunnels

gherve
Level 1
Level 1

Hi erveryone,

I am currently out of ideas and in a bad situation.

 

We have around 10 vpn IPsec site-to-site with our clients and our offices for a long time (months or years).

We have also some users remotly connected from their home

For a couple of days, everyday between 10:00 and 15h00 (french time), some of them goes down for few seconds and goes up at the same time. Users and site-to-site.

Many times every day.

 

My ISP has rebooted the CP.

I have checked many times the difference between tunnels which stays up and those who goes down.

Nothing.

The only things weird is I have "NAT/PAT pool exhausted" in the logs

If I do 

show conn count

I got : 3272 in use, 65913 most used

 

When tunnels goes down, I have his message in the logs :

deny esp reverse path check on interface outside

 

Any ideas ?

Thanks

G.

2 Replies 2

Dennis Mink
VIP Alumni
VIP Alumni

if the ASA recevies a packet on and interface and the ASA's routing table has that subnet/route on another interface - reverse path checking will drop it.

 

is suspect you have a routing issue/flaping route, check routingtable first

Please remember to rate useful posts, by clicking on the stars below.

After another reboot of the 2 units (active and standby) no disconnections this morning.

Keep going and cross fingers.

Review Cisco Networking for a $25 gift card