11-08-2012 09:31 AM
I have an ASA 5510 at V8.2(5) with something near 20 site to site VPN tunnels. I am having a problem with 1 tunnel to a RVS4000. The tunnel is completely closed and reset during Phase2. Here is a small snipet at the time of the tunnel reset
x.x.x.x, Username = x.x.x.x, IP = x.x.x.x, Session disconnected. Session Type: IPsec, Duration: 7h:36m:30s, Bytes xmt: 333755, Bytes rcv: 86281, Reason: User Requested
Followed by
Group = x.x.x.x, IP = x.x.x.x, Active unit receives a centry expired event for remote peer x.x.x.x.
We use a number of connection oreinted sessions and this blowing them out of the water. all other tunnels are up for DAYS to more than a Month.
How can I prevent this reset from happening?
Thanks
11-08-2012 09:37 AM
What is the time interval? Or is it random?
11-08-2012 10:08 AM
Timers for IPSec and IKE are set to 28800 ( 8hrs ). Reset is happening at roughly 7hrs 35min ( give or take a minute or 2)
11-08-2012 10:15 AM
Have you tried to increase the timers to 24 hours instead?
11-08-2012 10:20 AM
We tried that last night and still waitning to see the results. While 24hrs is better than reseting 3 times a day, it is not consistant with how other devices are acting. Is this a limitation of the RVS4000
11-08-2012 10:35 AM
With 24 hours you might not even have to do it at all. I'm not sure about RVS4000, never used it unfortunately. Were you able to change it on both sides or just the ASA?
11-08-2012 10:37 AM
It has been set on both devices...Guess we wait and see. Should know in about 4hrs
11-08-2012 10:38 AM
I'm curious myself too now as I have not dealt with the RVS4000 post back the results if you can.
11-08-2012 02:32 PM
Well 23.5 hours and it reset. I will cause a reset at O'Dark O'Clock ( 3am router time ) when no one is on the VPN so this will be less of a problem until I can sort it out.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide