12-03-2020 10:29 PM
Hi All,
We have multiple IPSec tunnels configured on Cisco FTD FW. We'll monitor all those tunnels on our monitoring system.
We want to make provision that Tunnels should only goes down whenever there is some reachability issue on either of the internet links i.e. Tunnel should UP even in case there is no traffic...probably this require some Keepalive mechanism and configuration. Just to support and make monitoring more accurate.
Point to remember here that only Remote end configuration and support are not controlled from our end. We have to plan supporting new configuration(If any) at Cisco FTD end only.
regards
12-04-2020 12:33 AM
Once you build the VPN Phase 1 will be always up and running between devices. only you do not see phase 2 since there is no interesting traffic not processing.
its not a good practice to keep VPN open all time when there is no intresting traffic. available.
But you can do other option you can setup a monitoring system like NMS in the intresting traffic allow ping to SNMP to monitor other side network to meet your requirement.
if you looking to keepalive this explains a bit of it.
12-04-2020 08:03 AM
May I add one more option here:
Alternatively, he may consider to set the idle-timeout from default 30-minutes to none.
It's easy to do on ASA, but may require "FlexConfig" on FTD.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide