cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
622
Views
0
Helpful
1
Replies

Ipsec - Packet Lost

mohsen.hosseini
Level 1
Level 1

Hi,

I have a problem in Site to Site VPN between 2 Cisco 3662 routers:

Issue:

I configed the Ipsec Tunnel according the following URL , and after that i can ping the other side of the tunnel , but there are so many packet lost !

http://www.cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a0080094634.shtml

Any help would be much appreciated.

Many thanks...

1 Reply 1

b.hsu
Level 5
Level 5

The issue canbe resolved as in the below, Try and check out these options:

If the VPN Client is located behind a device that performs Network Address Translation (NAT)/Port Address Translation (PAT), make sure that the translation does not timeout for the client.

Make sure the IKE keepalives are enabled. In some situations, it may be necessary to disable this feature to solve the problem (For example, if the VPN Client is behind a firewall that prevents DPD packets). To disable the IKE keepalives, perform these steps:

Select Configuration > User Management > Groups

Select a VPN Client group that you are working with, and click Modify

On the IPSec tab, uncheck the IKE Keepalives box

Check the timeout settings on the VPN Concentrator and on the VPN Client. The timeout settings are found on the General tabs of the base group, group, and user settings (under Configuration > User Management)