06-20-2006 04:11 PM - edited 03-09-2019 03:19 PM
We have remote offices using EZvpn on PIX 506e to connect to corporate.
To prevent tunnel to go down we had to use the command "vpnclient nem-st-autoconnect"
We are now trying to replace the 506e with an IOS router.
What is the command equivalent on IOS to keep tunnel up when there is no traffic
crypto isakmp keepalive X X doesn't work.
The only solution I can think off for the moment is to use object tracking to have the router ping every few minutes to keep the tunnel alive.
Is there a better solution?
Thanks
06-20-2006 07:56 PM
You may try to use Lan-to-Lan VPN for long time tunnel up.
06-20-2006 10:25 PM
or you can try modify idle timer:
Rack01R2(config)#crypto ipsec security-association idle-time ?
<60-86400> Idle time at which IPSec SAs are deleted
06-22-2006 05:22 AM
Under the crypto configuration for the client on the IOS router (e.g. crypto ipsec client ezvpn xyz123), set "mode network-extension". Further, you can also configure "connect auto" under the same sub-level.
Those are the equivalent of the PIX command.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide