cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
415
Views
0
Helpful
2
Replies

VPN Connection comes down after roughly 8 Minutes inactivity

richard.werner
Level 1
Level 1

Hi all,

One of our customers uses Cisco VPN Clients for Windows to connect to a Cisco Pix 500.

The clients are behind a Linux NAT firewall.

The Problem we have here, is not that the VPN connection isn't working but it's coming down after (moraless) exactly 8 minutes of inactivity. It does stay up if the connection is busy and it also stays up, if the connection is made without a NAT device.

I already checked the logfiles on the NAT firewall, there is no sign of any packets being dropped after that period of time. Also, I tried sniffing traffic on the client side of the connection, there are no additional (since the connection itself is idle) packets being dropped.

What I'd need to know here is, how Cisco VPN does work and what could be the reason for this "tunnel timeout", which only takes place behind that NAT gateway.

Are there any special IP protocols (like GRE or SWIPE) involved?

Thank you very much for your support!

Richard

2 Replies 2

ehirsel
Level 6
Level 6

Enable logging on the cisco vpn client, and set the log level to 3 for IKE, connection manager, and the daemon. Then have a client behind the NAT device connect. Then when the connection ends, post the log results here.

One question: When you did the sniffer tracing, were you between the client and the nat device, or between the nat device and the pix?

Hi Edward,

thanks for your reply, I past your Info on and I

am still waiting for answer.

Regards

Richard