cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1384
Views
70
Helpful
11
Replies

IPSEC VPN IKEv2 when drops it doesnt recover automatically

mze
Level 1
Level 1

IPSEC VPN when drops it doesnt recover automatically on ASA5508 

 

11 Replies 11

@mze do you have dead peer detection (dpd) keepalives configured on both ends? This will clear the stale IPSec SAs.

Are you using IKEv1 and are the lifetimes identical?

thank you for quick response , I see below configration of the IPSEC , I dont see any DPD configration is there command for this . 

 

 

@mze refer to this link for the command.

https://community.cisco.com/t5/security-documents/dead-peer-detection/ta-p/3111324

 

You need to ensure DPD is configured on both devices.

 

DPD is configured , but tunnel doesn't  come up untill I clear it .

what is other Peer FW? is it ASA also ?

YES both are ASA5508 

are one of peer use the default group-policy?

config idle-timeout/Session-timeout to be none for group-policy in both
try this way. 

mze
Level 1
Level 1

thanks 

 

 

 

can you share the config for both peer ? 
you don't mention in your post that you use IKEv2, anyway
crypto map outside_map 1 set pfs group5<- check this command are enter on both peer. 
try and monitor the tunnel status.

thanks 

 

ASA UK
crypto ipsec profile ...
 set ikev2 ipse-proposal ....
 set pfs group24
 responder-only <- this need 

ASA AU

crypto ipsec profile ...
 set ikev2 ipse-proposal ....
 set pfs group24

try the above config other config is OK.