cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3099
Views
5
Helpful
25
Replies

Redundancy VPN Site to Site using with dual ISP on cisco ASA

Sotheng Se
Level 1
Level 1

 

Dear Supporter,

Could you help me to provide configuration for network diagram as in attached file.

 

I'm appropriate with your help.

 

thank you

 

Best Regards

 


 

25 Replies 25

 

Dear nkarthikeyan,

Any update for my issue?

 

thank you

Best Regards,

sotheng

 

Dear nkarthikeyan,

Could you let me know about my issue?

it is also urgent issue.

thank you

Best Regards,

sotheng

 

Hi Sotheng,

 

I have tried to setup a lab on that. But i was nt able to succeed with that due to some issues. I will try to do it again... but i cannot ensure that i will be able to succeed with that today also....

 

But on your configuration wise... It seems all okay.....

 

HTH

 

Regards

Karthik

 

Dear nkarthikeyan,

It's Ok for that.
Take your time!!!!

Anyway, thanks so much for your quick support and respond
 

 

thank you

Best Regards,

sotheng

 

Dear nkarthikeyan,

Any update for my issue?

 

thank you

Best Regards,

sotheng

Hi Sotheng,

 

Yes I am doing a lab on that. But i am getting closely the same result as you get... am getting 6 to 8 RTO during this fall back. I will let you know if i get any idea for reducing the RTO.

 

Regards

Karthik

 

Dear nkarthikeyan,

Thank so much for your quick respond. Now my customer want to close this case as soon as possible because it takes many days ago. Could you let me know as soon as possible whether it can reduce the RTO or not?

thank you

Best Regards,

sotheng

Hi Sotheng,

 

I suggest you to get the Cisco TAC case raised for this. They might be able to investigate and suggest to improve the performance. Thanks!!!

 

Regards

Karthik

 

Dear nkarthikeyan,

Thank for your help!!!!!!

Best Regards,

sotheng

Hi Sotheng,

 

I have got a clue to minimize the RTO over VPN fall back option.... can you try like the below for both the tunnels on both the ends with same configurations.... this actually helps in improving dead peer detection quite earlier than the usual time taken. you have to make changes in tunnel-groups at both the ends. try this out and let me know if this helps in improving the performance.

tunnel-group <peer ip> type ipsec-l2l
tunnel-group <peer ip> ipsec-attributes
 isakmp keepalive threshold 10

 

Regards

Karthik

 

Dear nkarthikeyan,

I tested the step that you provided me and the result is that:

When it switches from ISP1 to ISP2 it takes 30 to 35 second as before, but when it fall back ( from ISP2 to ISP1 ) it has only one timeout. Do you have any idea about this?

very very appreciate with your help!!!!

Thank for your help!!!!!!

Best Regards,

sotheng