Showing results for 
Search instead for 
Did you mean: 

Problem with loss packets with VPN (hub-spoke)

Level 1
Level 1


I have an ASA 5515X (9.1.5), and a four 5505 (9.1.5) installed at different sites, i have configured a vpn from each of this 5505 to the 5515X,

but i did a dynamic configuration, so there is not a tunnel group config.. and no IP address for each site.

I have problems with packet loss in the VPNs, i have configured QoS in the hub ASA considering problems with bandwidth, yesterday i did some ping from one ASA 5505 and i got 99% of successful pings, so i don't think it has something to do with bandwidth...

Any ideas what is causing this, (perhaps changing MTU, or do i need static tunnel configs)

these are the configurations, the vpn is established from the spoke, everytime is needed..



Juan Pablo

4 Replies 4



  * Try using the public interface of the ASA to make this test

  * Try sending ICMP traffic from you LAN to a public IP (e.g


- Are the ASAs dropping this traffic? Try a "asp drop" capture

ciscoasa# capture asp type asp-drop all

- What's the ICMP success rate to your local firewall in your LAN?


This questions can help you isolate where the drop is located.



The test i did yesterday was 100% successful!!, from the internet to the outside IP interface.

I wasn't able to test from the LAN to the Internet (i will do it)


From the local lan to the ASA is 100% successful..

But when i connect through access vpn to a spoke site, then ssh connection to the ASA 5505 (spoke ASA) and did extended pings to the LAN at the hub site i got 98% successful pings..

I will do the capture... so i could know if the ASA is dropping this could i realize that the asa is dropping the traffic?.

thanks for your help,


Hello jphvpichi,


ciscoasa# capture asp type asp-drop all
ciscoasa# show cap asp


The first command will configure the captures and the second one will show you the content of it.

If you see your traffic in this captures, it means that the ASA is dropping it. Check the previous link for more information.




By the way, when you mentioned that you tried from the internet to the outside. Was this traffic generated from outside to outside interfaces (between both ASAs)?



Hi alvillarroel,

thanks for your explanation!!, i forget to review the link,

I'll do the capture and let you know,
