cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
281
Views
0
Helpful
1
Replies

Tunnel collapsed although configured incident time out

astanislaus
Level 2
Level 2

VPN client left two hours with no traffic. Tunnel collapsed although configured incident time out. SHOW TECH and selected SYSLOG outputs attached.

Customer says it is not necessarily 2 hours all the time. So time idle connections can time out in 40 minutes or so.

Now

vpn-idle-timeout none

command is there under

group-policy DfltGrpPolicy attributes

1 Reply 1

thomas.chen
Level 6
Level 6

Try this :

Check the "keepalive" function on ASA, check the isakmp lifetime seconds [retry seconds] cmd configued with life time.

Try this link:

http://www.cisco.com/en/US/products/ps6635/products_white_paper0900aecd8034bd59.shtml