cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
429
Views
0
Helpful
2
Replies
Highlighted
Beginner

ASA VPN issue

We have site-to-site VPN IPsec tunnel step-up between HQ and multiple sites. It is a hub and spoke design.

Recently, we encounter a weird problem from one of our site VPN tunnel to our HQ.

The VPN tunnel for this site has been working fine for the past one year. Just last month, we encounter high delay between this site and our HQ.

When we do ping test between this site and HQ, we can experience up to 3000ms delay and even intermittent timeout.

If i do a vpn session logoff for this site, the round delay will fall back to about 70ms which is normal.

This will run for about a day or so and the delay will appear again. Almost daily, i have to do a vpn session logoff.

Some of the things i did:

1. reflash firmware to 8.2.1

2. reapply the crypto configuration

3. check syslog but nothing strange capture

4. getting ISP to check if they have any appliance blocking or throttling the IPsec traffic

Not sure if anyone here encounter such issue with ASA VPN. Hope someone can help? Thanks

2 REPLIES 2
Highlighted
Cisco Employee

Hi Koonmun,

This could be a memory leak issue also.

I would suggest going to the latest firmware as 8.2.1 is not the latest one. If the issue persists then contact TAC to open a case "when you are experiencing the issue", so the necassary information can  be captured.

Thanks,

Naman

Highlighted

Thanks Naman,

After all the testing, we decide swap to another ISP and everything back to normal again.

Seem like the original ISP did something on their network which affect our VPN tunnel.

We are awaiting for an answer from the ISP.