cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
554
Views
0
Helpful
2
Replies

VPN Connectivity

egoodman2
Level 1
Level 1

Has anyone ever had this happen. I have the configuration correct, because it works for a spell.Then after a certain amount of time it stops working and does not automatically begin. 

So here is the scenario:

I have a site to site configured. I have one side of it going along fat, dumb and happy, and then without warning connectivity is lost. I have the use attempt to ping the other site, but nothing. It is only until I connect to remote ASA and run the ASDM packet tracer forcing a connection that it begins to work again. But did I forget to mention, the first run on the packet tracer to the remote site fails. Only until I re run it does it connect and then all is okay. I thought it might have been a timeout issue, but that is 8 hours, then I thought it could be over the kilobyte issue, so I changed that to the default. 

I have run packet captures and until I force the connection the ping send are the only commands that register. Once I run the ASDM packet captures (twice), I then see the replies.

If someone has any suggestions I would love to hear them. The users are starting to band together, and seeing how this is nearing Halloween, I'm hoping they are not carrying pitchforks.   

1 Accepted Solution

Accepted Solutions

balaji.bandi
Hall of Fame
Hall of Fame

Generally you need to check idle time out(i believe you have checked again)

 

again just verify  "Verify Idle/Session Timeout"

https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/81824-common-ipsec-trouble.html#solution13

 

As per your description as soon as you start traffic the ipsec establishing the connection. ( generally below solution not required) idle time out should solve the issue.

 

If not  you can setup a ping with EEM Script to keep the live traffic on.

 

https://www.cisco.com/c/en/us/support/docs/security/adaptive-security-appliance-asa-software/117883-config-eem-00.html

 

or post the complete config both the side to review and some logs if you have captured any when the connection lost.

 

 

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

View solution in original post

2 Replies 2

balaji.bandi
Hall of Fame
Hall of Fame

Generally you need to check idle time out(i believe you have checked again)

 

again just verify  "Verify Idle/Session Timeout"

https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/81824-common-ipsec-trouble.html#solution13

 

As per your description as soon as you start traffic the ipsec establishing the connection. ( generally below solution not required) idle time out should solve the issue.

 

If not  you can setup a ping with EEM Script to keep the live traffic on.

 

https://www.cisco.com/c/en/us/support/docs/security/adaptive-security-appliance-asa-software/117883-config-eem-00.html

 

or post the complete config both the side to review and some logs if you have captured any when the connection lost.

 

 

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

I gave it at try lets see what happens.