Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Cisco PIX to Cisco VPN drops connection periodically

Posted on 2004-09-02
6
Medium Priority
?
622 Views
Last Modified: 2011-04-14
I have a Cisco Pix 506e connecting via a T1 line to a Cisco Device on the other end. I'm not exactly sure of the device on the other end, but it does handle multiple VPNs without the others having problems.

Currently to fix it we turn it off then on and it and it resolves the problem.

I'm looking to determine the cause. What commands are available on the PIX to try to diagnose the problem? Are there any third party tools available to help?

Thanks,
Ron
0
Comment
Question by:youritstaff
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 11

Assisted Solution

by:billwharton
billwharton earned 400 total points
ID: 11963222
No third party tools i have come across.

You could use these commands which show you the state of your connection and the debug commands show you live output for your vpn tunnels.
show crypto ipsec sa
show crypto isakmp sa

debug crypto ipsec
debug crypto isakmp
0
 

Author Comment

by:youritstaff
ID: 11963884
Thank you for your post. I've used those command initially to debug the initial connectivity. I didn't think they'll help me in this instance. Is there anyway to write the output to a log file so that I can go through the info after an outage.

Also, is there any way to check for memory leaks?

Thanks again.
0
 
LVL 36

Assisted Solution

by:grblades
grblades earned 400 total points
ID: 11964280
Hi youritstaff,
Check to see what IOS version the remote device is running and see if you can get an upgrade. This might be free if the problem you are experiencing is a known problem.

Also check the key lifetimes are set to identical values at both ends.
0
Looking for the Wi-Fi vendor that's right for you?

We know how difficult it can be to evaluate Wi-Fi vendors, so we created this helpful Wi-Fi Buyer's Guide to help you find the Wi-Fi vendor that's right for your business! Download the guide and get started on our checklist today!

 
LVL 1

Accepted Solution

by:
clkemp earned 800 total points
ID: 11966155
How often does it drop? Weekly? Daily? Hourly?  Can you post the crypto section from the pix with passwords and ip's changed?  If you have the same info from the host end, please post it too.  More information will help diagnose the problem.

You can send system messages to a syslog server.  Pick up a syslog server for windows from Kiwi software (www.kiwisyslog.com).  Setup your pix to send all messages to the syslog server.

logging on
logging host server_ip_address
logging facility 20
logging trap informational
0
 
LVL 1

Assisted Solution

by:tevens
tevens earned 400 total points
ID: 11973634
Most likely the reason why you can re-establish the connection on reboot is because one side adjusts to match your config during establishment.  Verify that both ISAKMP and IPSEC proposals match on both sides.  Make sure that both sides select the correct proposal first.  Sometimes the problem lies with having the proposal order the same on both sides.

--Tim
0
 

Author Comment

by:youritstaff
ID: 12373882
Thank you everyone for your help. It turned out to be the linksys switch between the cisco router and switch. I distributed the points as they all helped in one way or another.
0

Featured Post

Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A 2007 NCSA Cyber Security survey revealed that a mere 4% of the population has a full understanding of firewalls. As business owner, you should be part of that 4% that has a full understanding.
This program is used to assist in finding and resolving common problems with wireless connections.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…
Suggested Courses

650 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question