cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
Webcast- Catalyst 9000
254
Views
0
Helpful
1
Replies
Highlighted
Beginner

VPN unavailable when WAN connection lost

I am trying to troubleshoot an issue with our VPN reachability. Everything functions normally when our WAN connection is up but when our WAN connection is lost we can no longer connect to the VPN.

It's a fairly simple design and the VPN users are authenticated back to our WIN2K8 server that resides on the LAN segment (see diagram)

Under normal conditions I can ping the outside interface of the ASA from the internet. When our WAN connection between HQ and remote router drops I can no longer ping it from the internet.

This is a remote site so we have not been able to perform onsite testing so we have an "outside only" viewpoint of the issue.

I've been beating my brain on this one. I see no reason why the one would affect the other. Any one have some ideas?

VPN Diagram.jpg

1 REPLY 1
Beginner

VPN unavailable when WAN connection lost

I have just discovered that we are using NT-Domain for the AAA authentication. I know this is a bit outdated. Could that be the source of our issue? The AD server does exist in a Windows environment with more than one AD server, including our main radius server that is back in HQ.