PIX 515e 7.1(1) Tunnels Dropping at about 31 mins %PIX-4-113019

I have some tunnels on the firewall that are coming down if there is no interesting traffic.  They are all coming down right around 31m:3xs.  I can't seem to find the timeout issue here and would like to keep the tunnels up if possible.

%PIX-4-113019: Group = <group-ip-address>, Username = <Group-ip-address>, IP = <Group-ip-address>, Session disconnected. Session Type: IPSecLAN2LAN, Duration: 0h:31m:43s, Bytes xmt: 60, Bytes rct

Thanks in advance
LVL 1
ort11Asked:
Who is Participating?
 
lrmooreConnect With a Mentor Commented:
I don't think so. It's just an example
The default is 28,800 seconds (eight hours).
By shortening the lifetime you force re-negotiation earlier.
0
 
lrmooreCommented:
>are coming down if there is no interesting traffic.
This is by design. IPSEC tunnels are dynamic and depend on interesting traffic. Setup a periodic (like every 15 minutes) ping on a cron job or something from one workstation to something on the other side.

You can adjust the security association lifetime:
 >crypto map mymap 10 set security-association lifetime seconds 2700  <== 45 minutes



0
 
ort11Author Commented:
Ok, is 2700 the max on the lifetime?

0
 
ort11Author Commented:
Please do not stop this thread.  We are still having an issue and would like to keep this open.  Thanks
0
 
Keith AlabasterEnterprise ArchitectCommented:
If no response is received to LRMoores last post to you or an update on the current position is not posted I will be putting this back in the queue on my next round of cleanups which will be next week.

Thanks
Keith
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.