cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2378
Views
0
Helpful
9
Replies

Cisco ASA Site-to-Site VPN connection always reestablish

muhammadaswad
Level 1
Level 1

Can someone help me... I have two Cisco ASA 5506... I've already configured the Site to Site VPN connection.......The VPN connection was established like normal........... the problem is, the VPN connection always dropped, and then it will establish again, this happened frequently ...... Does anyone have an idea of how I could fix this problem?...........or this problem is related to the ISP connection?

 

FYI, I do the PPPOE at the router site before reach to Cisco ASA

2 Accepted Solutions

Accepted Solutions

balaji.bandi
Hall of Fame
Hall of Fame

You need to look the logs while vpn tear down and post the logs hee, with what ASA  code you running, and let us know what is other end VPN devices ?

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

View solution in original post

Check lifetime of tunnel, make it longer and disable kbytes lifetime.

View solution in original post

9 Replies 9

balaji.bandi
Hall of Fame
Hall of Fame

You need to look the logs while vpn tear down and post the logs hee, with what ASA  code you running, and let us know what is other end VPN devices ?

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

the other end was a Cisco ASA 5516, is this the right log location Monitoring->Logging->Log Buffer ?

I try to retrieve log from the previous day, but I can just only display all the log for today only.

Check lifetime of tunnel, make it longer and disable kbytes lifetime.

agree with @MHM Cisco World also you could run continious pings from your one machine in your network toward the other end of the vpn network. doing so the tunnel will be keep up. it could be going down when there is no traffic passing in the tunnel and due to ideal time vaule the firewall tear down the vpn tunnel.

please do not forget to rate.

Is this the correct location to check tunnel  lifetime  Configuration > Site-to-Site VPN > Connection Profiles >Advanced >Tunnel Group > IKE Keep-alive........ is this the right location ?

You need to match both sides. here is the site to site VPN config using ASDM.

 

https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/119141-configure-asa-00.html

 

You need to post the Logs what is the reason of teardown, rather we assume many scenarios why it went down, so you can tweak the config.

 

if you running IP SLA or IGP between site, you always have active traffic so it won't affect due to idle times.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

I've already follow this link

https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/119141-configure-asa-00.html 

 

and the result is  Site to Site VPN already up for 24 hour  without dropping.......is it save if I've share the log here? 

Noted........Yeah, my configuration already being configured like this. 

Review Cisco Networking products for a $25 gift card