cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
572
Views
5
Helpful
3
Replies

site to site vpn

bluesea2010
Level 5
Level 5

Hi,

I am running  site ti site ipsec vpn  (asa 5580) , the  first  one or two packet always fail when I ping 

 

What could be the reason 

 

Thanks 

3 Replies 3

Hi,

This is because the VPN is down. You need 1 or 2 packets to trigger IPSEC
negotiations and establish IPSEC SA. While the negotiation is taking place,
the packets intended to pass through the tunnel will be dropped.

**** please remember to rate useful posts

Hi,

How to solve this issue 

 

Thanks

Hi,

Run a continuous traffic between nodes such as IP SLA every 5 mins. This
will keep the tunnel IP as the traffic will always be present. Otherwise,
disable SA idle timeout to make it continuous which is not recommended.

IP SLA examples
https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipsla/configuration/15-mt/sla-15-mt-book/sla_icmp_echo.html

**** please remember to rate useful posts