cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
998
Views
0
Helpful
5
Replies

ASA IKEv2 Site to Site with Multiple Peers

mumbles202
Level 5
Level 5

I'm setting up a site to site vpn between 2 5516s, both running 9.14.  Each of the 2 sites has 2 ISPs and each is configured to have both of the far end ip addresses as peers in the vpn configuration and has a matching tunnel-group for each of the ISPs.  If site A has a vpn up to site B over that sites main ISP and the primary ISP at site B goes down, it takes about 5 minutes in order for the vpn to establish and start passing traffic over the backup ISP.  Internet access is immediate(I can ssh to the ASA w/o any issues), but the vpn takes some time to re-establish.  As the dns server is across that vpn it causes an issue as computers are eventually down until they can re-establish connection back to the dns server.  Once the tunnel comes up all works as expected.  

 

If I recall correctly this was never an issue before when the site to site tunnel was using IKEv1.  I'll test failover of Site A ISPs later today but wanted to see if there might be something I'm missing that would account for this.  

5 Replies 5

@mumbles202 do you have Dead Peer Detection (DPD) keepalives configured? this will detect stale IPSec SAs.

You might want to look at running VTI's and a routing protocol over the tunnel, it will detect failure quicker.

Yes, on each of the tunnel-groups I have this configured:


isakmp keepalive threshold 10 retry 2

Thanks for the link. That should accomplish the connectivity, though it seems to be limiting on first read.  For example, if ISPB at 1 site is down at the same time as ISPA at the other, there seems to be no way to establish a tunnel since it's ISPA-ISPA and ISPB-ISPB.  The setup I was going for was that the either ASA can establish a vpn tunnel to each of the other sides ISPs just in case of an odd outage issue like described above.  Using IKEv1 this wasn't an issue and the failover happened fairly quickly after the track went down on either ASA.  

hard to answer why IKEv1 is failover but IKEv2 is not.