cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
985
Views
0
Helpful
3
Replies

ASA to ASA - IPSEC LAN-To-LAN VPN - Telnet sessions die

smunzani
Level 1
Level 1

Hi,

I have observed that after a few minutes of idle time(no  key strokes) the telnet sessions drop for my lan-to-lan tunnel between an ASA5505 and ASA5510. Since telnet doesn't have keepalive function, is there any cisco option for lan to lan VPN keeplive that I can leverage? An alternative here is make changes to IPSEC timeout values but that's not a good thing to do. I disabled PFS just in case that's causing the session to drop but that didn't help.

Thanks,

Sam

3 Replies 3

Roman Rodichev
Level 7
Level 7

Disable DPD under tunnel-group (isakmp keepalive disable)

I just changed it. I will know how it goes in a few.

So PFS has nothing to do with this and I can potentially enable PFS?

Thanks,

Sam

PFS makes IPSEC SA keys more secure, and shouldn't cause what you are experiencing