We have a Cisco ASA 5520. The ASA has been in place for about 4 yrs. We have about 15 Site to Site VPNs configured on it. These S2S vpn connections have been in place for a few years now. In the last month, we've had two instances where 95% of the sites have lost connectivity back to this ASA. When this happens, we cannot connect to the firewall via the ASDM or via SSH.
The only solution is to power cycle the firewall. Once we do that, all the VPN connections come back up normally.
The two incidents occurred about 3 weeks apart. As mentioned earlier, there were no issues with the VPN or these connections before this month.
Any ideas as to what may be causing this, or how I can go about troulbeshooting?
... View more
We've been experiencing intermittent connectivity issues to external sites from one machine. What happens is when trying to connect to an external site either by DNS or up, the connection takes a long time. Sometimes we get a message that the connection timed out. Eventually after a few minutes we are able to connect. This is only happening to one server in my network. The other servers in the same clan do not experience this issue. This environment has been up for a couple of years now and this started after we rebooted the server. We did have logmein hamachi and another logmein agent running on the machine which have been uninstalled.
Here is our environment:
Windows 2012 datatcenter server running on a highly available VMware esxi 2 node cluster.
Cisco 3750 cluster
Cisco 5520 firewall.
There are a few vms in this environment but this one vm is the only one experiencing this issue and it seems to have started after rebooting the vm.
Here's what I've tried so far:
Changed DNS servers on vm (no effect)
Changed virtual nic on vm (no effect)
Disabled ipv6 on vm (no effect)
Failed over vm to other node to eliminate host related issues (no effect)
Failed over another vm to the same host that my problem vm is on to duplicate the issue (the other vm didnt experience the issue)
Changed the IP address of the server. This is the only thing that seemed to work, but I can't change the IP address of the server due to the application running on it.
So it has something to do with the IP address of this box. Any ideas on how I can troubleshoot and fix this issue?
... View more
here is our enviornment:
Windows 2012 R2 Standard virtual machine running vsphere hosts running vsphere 5.5.
Connected to a Cisco 3750x Stack
Connected to a Cisco ASA 5520
right now, all the virtual machines are running on one host. All virtual machines are on the same VLAN.
There is one virtual machine that is having trouble sending external requests to the internet. Here's what I've tried so far:
I can ping the internal interface of the ASA.
I CANNOT ping the switch from the server
I can ping the server from the switch.
I cannot ping an external address (i.e. 18.104.22.168)
i cannot ping other vlans from the server
I can connect to the server when I'm on teh same vlan, and machines that are accessing the server via site to site vpn can access the server as well, but that's about it.
the the other virtual machines on the same vlan and on the same vswitch can ping other vlans, access the internet, etc.
Any ideas on how to troubleshoot and resolve this issue?
... View more