08-03-2005 02:23 AM - edited 02-21-2020 01:53 PM
We are using IPSEC 3DES tunnel between Cisco router and PIX firewall. Initially this tunnel worked fine. But now I am seeing the tunnel is breaking after every 30 seconds and if there is any interesting traffic then initiates again and keeps flapping. Due to which I am seeing the traffic is flowing and encrypted from router to PIX but reveres way traffic is not getting encrypted. If any one having answer please update.
Router#sh crypto isakmp sa
dst src state conn-id slot status
10.227.40.4 10.227.40.34 QM_IDLE 4 0 ACTIVE
10.227.40.34 10.227.5.4 QM_IDLE 368 0 ACTIVE
10.227.40.34 10.227.5.4 MM_NO_STATE 367 0 ACTIVE (deleted)
08-09-2005 05:50 AM
Concentrator and firewall headends often support fail-over capabilities in an active/standby configuration. When the primary fails, the secondary unit assumes the IP and Media-Access-Control (MAC) address of the primary, and the tunnel reestablishment commences. Routers function in an active/active configuration. Both headend devices will allow tunnel establishment. You might consider using IKE keepalives in the headend for heterogeneous remote-site device support. There is no IETF standard for keepalives today, only proposals, and thus this mechanism will work only with products from a single vendor. If a momentary loss of connectivity occurs at a remote site, it may establish a new tunnel with the secondary (but always active) headend device. Because tunnel establishment does not affect the routing table unless routing protocols are running over the tunnel, the routing state in the headend will not change. When the tunnel switches between the headends because of the remote-site flapping, the next-hop router will not be able to determine which active headend device has a valid path to the remote site. Flapping occurs when the remote site temporarily loses WAN connectivity. In order to avoid this issue consider using HSRP and reverse-route-injection (RRI). RRI works by modify the routing table on the device to reflect tunnel SA status.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide