09-13-2022 02:35 PM
IPSEC_LAN-LAN: ISAKMP-SA is not clearing for some of the site even peer router is down.
But still HO Router is sending--> ISAKMP<206> Identity Protection (Main Mode).
I have DPD: crypto isakmp keepalive 40 20 periodic
But still observing HO Router is keep sending packets for IKE1. Keepalive is configured globally to the HO
09-13-2022 02:39 PM - edited 09-13-2022 03:46 PM
Hi, I do the test,
if you config keepalive after the ISAKMP is active the keepalive not effect,
try clear isakmp and then check the keepalive again.
09-14-2022 01:43 PM
Hi Sir, Keepalive is set only in HO Router and its global configuration. Keepalive already configured in HO Router in beginning and we have more than 400 remotes.
09-14-2022 02:32 PM
""In order for ISAKMP keepalives to work, both VPN endpoints must support them.""
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide