cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
478
Views
0
Helpful
1
Replies

IPSEC site to site VPN, multiple VLAN intermittent

J_Vansen_S
Level 3
Level 3

hi all,

We have a simple Site to Site VPN using ipsec between 2 units of Cisco ASA.

CIsco ASA 5585 (HQ) and CIsco ASA 5555(Remote Site)

On my remote site, i have multiple vlans. We are having user complains saying that a few of the user vlans tunnel across no longer works after running for awhile.

Eg VLAN 50, 51,55 works, and VLAN 52,60 does not work.

We have configured to pass all the said vlans as interesting traffic.

When we sent out engineers down. It seems like the workaround is to ping to any VLAN network across to HQ, and the tunnel will be up automatically.

What could be the cause of the problem?

1 Reply 1

Aditya Ganjoo
Cisco Employee
Cisco Employee

Hi,

It depends on the NAT and the VPN config on the device.

If you are using a dynamic NAT then tunnel would only initiated by the source subnet.

Also could you share the relevant config for the affected tunnel ?

Regards,

Aditya

please rate helpful posts.