cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5509
Views
0
Helpful
2
Replies

Can we automatically renegotiate Phase 2 SA so that VPN tunnel stays up even if no traffic?

mitchen
Level 2
Level 2

We have a site-to-site IPSEC VPN with Cisco ASA5520 at our end and a Fortigate firewall at the other end (maintained by a 3rd party company)

To cut a long story short, we want to be able to keep the VPN connection up at all times (i.e. even when there is no “interesting traffic” passing)   Is there any means to do this other than e.g. sending a continuous ping across it?

The Fortigate people tell me they have a feature called “autokey keepalive” which would achieve this if they had a Fortigate at each end of the connection (it ensures a new SA is negotiated even if there is no traffic so that the VPN tunnel stays up)

Is there a Cisco equivalent that we could implement at our end?   I’ve not heard of anything similar with Cisco – can anyone confirm? And, if no specific feature, is there any workaround to achieve this with Cisco?

1 Accepted Solution

Accepted Solutions

olpeleri
Cisco Employee
Cisco Employee

Hello,

On IOS or ASA such kind of feature does not exists.

However, U can trick that either by configuring IP SLA on an inside device [ within the inside subnet].

Cheers,

Olivier

View solution in original post

2 Replies 2

olpeleri
Cisco Employee
Cisco Employee

Hello,

On IOS or ASA such kind of feature does not exists.

However, U can trick that either by configuring IP SLA on an inside device [ within the inside subnet].

Cheers,

Olivier

Hi Olivier, thanks for the info - I'll implement IP SLA as a workaround for this then.